Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. tactic: TA0005 ✕
Download CSV Show ATT&CK heatmapExecutable moved to Windows system folder Informational 4 variations
An attacker may be trying to avoid detection by moving an executable to a Windows system folder.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Stealth (TA0005)ATT&CK techniques: Masquerading (T1036)Required data: XDR AgentDetector tags: EDR Windows Disguised ProcessesAttacker's goals: An attacker may be trying to avoid detection by moving an executable to a Windows system folder.Investigative actions: Check if the file is known in organization or malicious. Check if the digital signature of the file is valid and belongs to a known good software vendor. Investigate the process that has moved the file to the system folder.Variations
Rare executable moved to Windows system folder by rare causality actor
Medium overridden
An attacker may be trying to avoid detection by moving an executable to a Windows system folder. overridden
Executable moved to Windows system folder by remote causality and a rare actor
Medium overridden
An attacker may be trying to avoid detection by moving an executable to a Windows system folder. overridden
Rare executable moved to Windows system folder by rare actor
Low overridden
An attacker may be trying to avoid detection by moving an executable to a Windows system folder. overridden
Executable moved to Windows system folder by rare and unsigned actor
Low overridden
An attacker may be trying to avoid detection by moving an executable to a Windows system folder. overridden