Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. technique: T1059 ✕
Download CSV Show ATT&CK heatmapCommonly abused AutoIT script connects to an external domain Medium
AutoIT scripts have legitimate uses, but are often abused by malware to execute in a signed process context.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Exfiltration (TA0010) Execution (TA0002)ATT&CK techniques: Command and Scripting Interpreter: AutoHotKey & AutoIT (T1059.010) Automated Exfiltration (T1020)Required data: XDR AgentAttacker's goals: Communicate with malware running on your network to control malware activities, perform software updates on the malware, or to take inventory of infected machines.Investigative actions: AutoIT scripts have legitimate uses, but are often abused by malware to execute in a signed process context. Identify the process contacting the remote domain and determine whether the traffic is malicious.