Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters. technique: T1055 ✕

Download CSV Show ATT&CK heatmap
  • Executable created to disk by lsass.exe Medium

    Lsass.exe does not normally create executables to disk. This activity was seen as part of several exploits, like EternalBlue and DoublePulsar, used during the WannaCry attacks.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    6 Hours
    ATT&CK tactics: Stealth (TA0005)
    ATT&CK techniques: Process Injection (T1055)
    Required data: XDR Agent with eXtended Threat Hunting (XTH)
    Attacker's goals: This activity was an important stage for several exploits.
    Investigative actions: Check the file that was written to the disk for malicious activities.