Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters.

Download CSV Show ATT&CK heatmap
  • Execution of renamed lolbin Informational 1 variation

    An attacker may be trying to avoid detection of lolbin's execution using a renamed lolbin.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Defense Evasion (TA0005)
    ATT&CK techniques: Masquerading (T1036) Masquerading: Rename Legitimate Utilities (T1036.003)
    Required data: XDR Agent
    Detector tags: EDR Windows Disguised Processes
    Attacker's goals: Detection avoidance via file rename.
    Investigative actions: Check the lolbin's origin or whether it comes with any packages the user has used.

    Variations

    Execution of significantly renamed lolbin

    Medium overridden

    An attacker may be trying to avoid detection of lolbin's execution using a renamed lolbin. overridden