Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source
  • Globally uncommon image load from a signed process Informational 5 variations

    A signed process loaded a DLL that, on a global level, it usually doesn't load.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Stealth (TA0005)
    ATT&CK techniques: System Binary Proxy Execution (T1218) Hijack Execution Flow: DLL (T1574.001)
    Required data: XDR Agent
    Detector tags: Global Anomaly Analytics, DLL Hijacking Analytics
    Attacker's goals: Attackers may use various methods to execute code in the context of a signed process to avoid detection.
    Investigative actions: Check if the actor process loaded a suspicious DLL before the alert. Check if the actor process was injected before the alert. Check if the process execution and connections are legitimate.

    Variations

    Globally uncommon image load from a signed process from a known vendor

    Medium overridden

    A signed process loaded a DLL that, on a global level, it usually doesn't load. overridden

    Globally uncommon unsigned image side loaded to a signed process

    Medium overridden

    A signed process side loaded an unsigned DLL that, on a global level, it usually doesn't load. overridden

    Globally uncommon and very rare image load from a signed process

    Medium overridden

    A signed process loaded a DLL that, on a global level, it usually doesn't load. overridden

    Globally uncommon image load from an injected thread in a signed process

    Low overridden

    An injected thread in a signed process loaded a DLL that, on a global level, it usually doesn't load. overridden

    Globally uncommon DLL was downloaded from an uncommon source and loaded by a signed process

    Low overridden

    A signed process loaded a DLL that, on a global level, it usually doesn't load. overridden