Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters.
Download CSV Show ATT&CK heatmapAn uncommon file was created in the startup folder Informational 4 variations
An uncommon file was created in the startup folder.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 7 Days
ATT&CK tactics: Persistence (TA0003)ATT&CK techniques: Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder (T1547.001)Required data: XDR Agent with eXtended Threat Hunting (XTH)Attacker's goals: Maintain persistence on the host through automatic execution at startup.Investigative actions: Determine if the file was created as part of a legitimate application installation, and check other files written by the same process. Identify which program opens this file based on its extension. Check the registry at HKEY_CLASSES_ROOT[extension]\shell[action]\command to see the default application or command used to execute the file.Variations
An executable file with a non-default extension was added to the startup folder
Medium overridden
An executable file with a non-default extension was added to the startup folder. overridden
An executable or script was added to the startup folder
Low overridden
An executable or script was added to the startup folder. This may occur during a legitimate program installation but could also indicate a malicious program persisting on the system. overridden
A file with an uncommon extension was added to the startup folder
Low overridden
A file with an uncommon extension was added to the startup folder, which may happen on new program installation, but may also indicate a malicious program persisting itself. overridden
A new shortcut (lnk) was added to the startup folder
Low overridden
A new shortcut (lnk) file was added to the startup folder, which may happen on new program installation, but may also indicate a malicious program persisting itself. overridden