Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters. technique: T1036 ✕

Download CSV Show ATT&CK heatmap
  • Common third-party software name masquerading Informational 2 variations

    An attacker might leverage common third-party software image names to run malicious processes without being caught.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Stealth (TA0005)
    ATT&CK techniques: Masquerading (T1036)
    Required data: XDR Agent
    Detector tags: EDR Windows Disguised Processes
    Attacker's goals: An attacker is attempting to masquerade as a common third-party software image to execute malicious code.
    Investigative actions: Investigate the executed process image and check if it is malicious. Investigate the actor process that executed the process and check if it is malicious.

    Variations

    Common third-party software name masquerading which was downloaded from an unexpected source

    Low overridden

    An attacker might leverage common third-party software image names to run malicious processes without being caught. overridden

    Common third-party software name masquerading with uncommon characteristics by actor with uncommon characteristics

    Low overridden

    An attacker might leverage common third-party software image names to run malicious processes without being caught. overridden