Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters. technique: T1547 ✕

Download CSV Show ATT&CK heatmap
  • Execution of an uncommon process at an early startup stage by Windows system binary Low 2 variations

    Uncommon execution of an executable found in an early startup stage by Windows system binary.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Persistence (TA0003)
    ATT&CK techniques: Boot or Logon Autostart Execution (T1547)
    Required data: XDR Agent
    Detector tags: Generic Persistence Analytics
    Attacker's goals: Attackers aim to get persistence to continue operating even after a reboot.
    Investigative actions: Check if the Causality Group Owner (CGO) has a related persistence mechanism that may have been abused by an attacker.

    Variations

    Execution of an uncommon process at an early startup stage by Windows system binary with suspicious characteristics

    Low overridden

    Uncommon execution of an executable found in an early startup stage by Windows system binary. overridden

    Execution of an uncommon process at an early startup stage by Windows system binary with uncommon characteristics

    Low overridden

    Uncommon execution of an executable found in an early startup stage by Windows system binary. overridden