Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters.

Download CSV Show ATT&CK heatmap
  • An uncommon executable was remotely written over SMB to an uncommon destination Low 3 variations

    An uncommon executable was remotely written over SMB to a destination, which was not involved in significant similar activity during last month.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Lateral Movement (TA0008)
    ATT&CK techniques: Remote Services: SMB/Windows Admin Shares (T1021.002)
    Required data: XDR Agent with eXtended Threat Hunting (XTH)
    Attacker's goals: Transfer tools as part of lateral movement activity across the network.
    Investigative actions: Verify if the shared file is malicious. Investigate if the file was executed on the host. Check the remote SMB client for other suspicious activities.

    Variations

    An uncommon executable was remotely written over SMB to a highly suspicious destination

    High overridden

    An uncommon executable was remotely written over SMB to a highly suspicious destination, which was not involved in significant similar activity during last month. overridden

    An uncommon executable with SCR extension was remotely written over SMB to an uncommon destination

    Medium overridden

    An uncommon executable with SCR extension was remotely written over SMB to a destination, which was not involved in significant similar activity during last month. overridden

    PsExec remote service component was remotely written over SMB to an uncommon destination

    Low overridden

    PsExec remote service component was remotely written over SMB to a destination, which was not involved in significant similar activity during last month. overridden