Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters.
Download CSV Show ATT&CK heatmapAn uncommon executable was remotely written over SMB to an uncommon destination Low 3 variations
An uncommon executable was remotely written over SMB to a destination, which was not involved in significant similar activity during last month.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Lateral Movement (TA0008)ATT&CK techniques: Remote Services: SMB/Windows Admin Shares (T1021.002)Required data: XDR Agent with eXtended Threat Hunting (XTH)Attacker's goals: Transfer tools as part of lateral movement activity across the network.Investigative actions: Verify if the shared file is malicious. Investigate if the file was executed on the host. Check the remote SMB client for other suspicious activities.Variations
An uncommon executable was remotely written over SMB to a highly suspicious destination
High overridden
An uncommon executable was remotely written over SMB to a highly suspicious destination, which was not involved in significant similar activity during last month. overridden
An uncommon executable with SCR extension was remotely written over SMB to an uncommon destination
Medium overridden
An uncommon executable with SCR extension was remotely written over SMB to a destination, which was not involved in significant similar activity during last month. overridden
PsExec remote service component was remotely written over SMB to an uncommon destination
Low overridden
PsExec remote service component was remotely written over SMB to a destination, which was not involved in significant similar activity during last month. overridden