Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters. tactic: TA0005 ✕

Download CSV Show ATT&CK heatmap
  • Execution of masqueraded third-party utility Informational 2 variations

    An attacker may be trying to avoid detection of third-party utility execution by renaming it.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Stealth (TA0005)
    ATT&CK techniques: Masquerading (T1036) Masquerading: Rename Legitimate Utilities (T1036.003)
    Required data: XDR Agent
    Detector tags: EDR Windows Disguised Processes
    Attacker's goals: Detection avoidance via file masquerading.
    Investigative actions: Check the process origin or whether it comes with any packages the user has used.

    Variations

    Execution of masqueraded third-party automation utility

    Medium overridden

    An attacker may be trying to avoid detection of third-party utility execution by renaming it. overridden

    Execution of significantly masqueraded third-party utility

    Low overridden

    An attacker may be trying to avoid detection of third-party utility execution by renaming it. overridden