Analytics Alerts
Browse the Cortex analytics alert reference.
2 alerts match the current filters. tactic: TA0003 ✕
Download CSV Show ATT&CK heatmapExecution of an uncommon process at an early startup stage Informational 2 variations
Uncommon execution of an executable found in an early startup stage.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Persistence (TA0003)ATT&CK techniques: Boot or Logon Autostart Execution (T1547)Required data: XDR AgentDetector tags: Generic Persistence AnalyticsAttacker's goals: Adversaries continuously find and develop new undetectable, novel methods of launching malware during startup. Attackers aim to get persistence to continue operating even after a reboot.Investigative actions: Check if the CGO (causality group owner) is familiar and if one of it configuration/parameters/registry keys has been modified.Variations
Execution of an uncommon process at an early startup stage with suspicious characteristics
Low overridden
Uncommon execution of an executable found in an early startup stage. overridden
Execution of an uncommon process at an early startup stage with uncommon characteristics
Low overridden
Uncommon execution of an executable found in an early startup stage. overridden
Execution of an uncommon process at an early startup stage by Windows system binary Low 2 variations
Uncommon execution of an executable found in an early startup stage by Windows system binary.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Persistence (TA0003)ATT&CK techniques: Boot or Logon Autostart Execution (T1547)Required data: XDR AgentDetector tags: Generic Persistence AnalyticsAttacker's goals: Attackers aim to get persistence to continue operating even after a reboot.Investigative actions: Check if the Causality Group Owner (CGO) has a related persistence mechanism that may have been abused by an attacker.Variations
Execution of an uncommon process at an early startup stage by Windows system binary with suspicious characteristics
Low overridden
Uncommon execution of an executable found in an early startup stage by Windows system binary. overridden
Execution of an uncommon process at an early startup stage by Windows system binary with uncommon characteristics
Low overridden
Uncommon execution of an executable found in an early startup stage by Windows system binary. overridden