Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

2 alerts match the current filters.

Download CSV Show ATT&CK heatmap
  • Execution of an uncommon process at an early startup stage Informational 2 variations

    Uncommon execution of an executable found in an early startup stage.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Persistence (TA0003)
    ATT&CK techniques: Boot or Logon Autostart Execution (T1547)
    Required data: XDR Agent
    Detector tags: Generic Persistence Analytics
    Attacker's goals: Adversaries continuously find and develop new undetectable, novel methods of launching malware during startup. Attackers aim to get persistence to continue operating even after a reboot.
    Investigative actions: Check if the CGO (causality group owner) is familiar and if one of it configuration/parameters/registry keys has been modified.

    Variations

    Execution of an uncommon process at an early startup stage with suspicious characteristics

    Low overridden

    Uncommon execution of an executable found in an early startup stage. overridden

    Execution of an uncommon process at an early startup stage with uncommon characteristics

    Low overridden

    Uncommon execution of an executable found in an early startup stage. overridden

  • Execution of an uncommon process at an early startup stage by Windows system binary Low 2 variations

    Uncommon execution of an executable found in an early startup stage by Windows system binary.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Persistence (TA0003)
    ATT&CK techniques: Boot or Logon Autostart Execution (T1547)
    Required data: XDR Agent
    Detector tags: Generic Persistence Analytics
    Attacker's goals: Attackers aim to get persistence to continue operating even after a reboot.
    Investigative actions: Check if the Causality Group Owner (CGO) has a related persistence mechanism that may have been abused by an attacker.

    Variations

    Execution of an uncommon process at an early startup stage by Windows system binary with suspicious characteristics

    Low overridden

    Uncommon execution of an executable found in an early startup stage by Windows system binary. overridden

    Execution of an uncommon process at an early startup stage by Windows system binary with uncommon characteristics

    Low overridden

    Uncommon execution of an executable found in an early startup stage by Windows system binary. overridden