Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters.

Download CSV Show ATT&CK heatmap
  • An uncommon file was created in the startup folder Informational 4 variations

    An uncommon file was created in the startup folder.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    7 Days
    ATT&CK tactics: Persistence (TA0003)
    ATT&CK techniques: Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder (T1547.001)
    Required data: XDR Agent with eXtended Threat Hunting (XTH)
    Attacker's goals: Maintain persistence on the host through automatic execution at startup.
    Investigative actions: Determine if the file was created as part of a legitimate application installation, and check other files written by the same process. Identify which program opens this file based on its extension. Check the registry at HKEY_CLASSES_ROOT[extension]\shell[action]\command to see the default application or command used to execute the file.

    Variations

    An executable file with a non-default extension was added to the startup folder

    Medium overridden

    An executable file with a non-default extension was added to the startup folder. overridden

    An executable or script was added to the startup folder

    Low overridden

    An executable or script was added to the startup folder. This may occur during a legitimate program installation but could also indicate a malicious program persisting on the system. overridden

    A file with an uncommon extension was added to the startup folder

    Low overridden

    A file with an uncommon extension was added to the startup folder, which may happen on new program installation, but may also indicate a malicious program persisting itself. overridden

    A new shortcut (lnk) was added to the startup folder

    Low overridden

    A new shortcut (lnk) file was added to the startup folder, which may happen on new program installation, but may also indicate a malicious program persisting itself. overridden