Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source
  • Adding execution privileges Informational 1 variation

    A script was granted execution privileges using chmod before being run.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Execution (TA0002)
    ATT&CK techniques: Command and Scripting Interpreter: Unix Shell (T1059.004)
    Required data: XDR Agent
    Detector tags: Kubernetes - AGENT, Containers
    Attacker's goals: Attackers may use chmod to grant execution privileges to scripts or binaries for malicious execution.
    Investigative actions: Verify that this activity is not part of normal IT operations. Check for similar commands executed on other hosts.

    Variations

    Adding execution privileges in a Kubernetes pod

    Informational overridden

    A script was granted execution privileges using chmod before being run. overridden