Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source
  • Executable moved to Windows system folder Informational 4 variations

    An attacker may be trying to avoid detection by moving an executable to a Windows system folder.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Stealth (TA0005)
    ATT&CK techniques: Masquerading (T1036)
    Required data: XDR Agent
    Detector tags: EDR Windows Disguised Processes
    Attacker's goals: An attacker may be trying to avoid detection by moving an executable to a Windows system folder.
    Investigative actions: Check if the file is known in organization or malicious. Check if the digital signature of the file is valid and belongs to a known good software vendor. Investigate the process that has moved the file to the system folder.

    Variations

    Rare executable moved to Windows system folder by rare causality actor

    Medium overridden

    An attacker may be trying to avoid detection by moving an executable to a Windows system folder. overridden

    Executable moved to Windows system folder by remote causality and a rare actor

    Medium overridden

    An attacker may be trying to avoid detection by moving an executable to a Windows system folder. overridden

    Rare executable moved to Windows system folder by rare actor

    Low overridden

    An attacker may be trying to avoid detection by moving an executable to a Windows system folder. overridden

    Executable moved to Windows system folder by rare and unsigned actor

    Low overridden

    An attacker may be trying to avoid detection by moving an executable to a Windows system folder. overridden