Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters.
Download CSV Show ATT&CK heatmapFile transfer from unusual IP using known tools Informational 1 variation
An adversary might use known tools to transfer tools/payloads into the compromised machine.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Command and Control (TA0011)ATT&CK techniques: Ingress Tool Transfer (T1105)Required data: XDR AgentDetector tags: Kubernetes - AGENT, ContainersAttacker's goals: Expand attack vectors and compromise the rest of the network.Investigative actions: Check if the action was done using an automation service. Check if there are any other suspicious activities originated from the same machine/executing user.Variations
File transfer from unusual IP using known tools in a Kubernetes pod
Low overridden
An adversary might use known tools to transfer tools/payloads into the compromised machine. overridden