Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters.

Download CSV Show ATT&CK heatmap
  • Conhost.exe spawned a suspicious cmd process Low 3 variations

    Attackers may abuse the conhost process to execute malicious files and evade detection.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Defense Evasion (TA0005)
    ATT&CK techniques: System Binary Proxy Execution (T1218)
    Required data: XDR Agent
    Detector tags: LOLBIN Execution Analytics
    Attacker's goals: Investigate the processes being spawned on the host for malicious activities.
    Investigative actions: An adversary may use the conhost process to evade detection.

    Variations

    Conhost.exe spawned a suspicious powershell encoded command

    High overridden

    Attackers may abuse the conhost process to execute malicious files and evade detection. overridden

    Conhost.exe spawned a suspicious scripting process with long command line

    Medium overridden

    Attackers may abuse the conhost process to execute malicious files and evade detection. overridden

    Conhost.exe spawned a suspicious child process

    Medium overridden

    Attackers may abuse the conhost process to execute malicious files and evade detection. overridden