Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. technique: T1569 ✕
Download CSV Show ATT&CK heatmapKnown service name with an uncommon image-path Low 2 variations
A Service with a known service name has an uncommon image-path.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Persistence (TA0003) Execution (TA0002)ATT&CK techniques: Create or Modify System Process: Windows Service (T1543.003) System Services: Service Execution (T1569.002)Required data: XDR Agent with eXtended Threat Hunting (XTH)Detector tags: Malicious Service AnalyticsAttacker's goals: Run malicious code within seemingly trustworthy services.Investigative actions: Investigate the image-path of the newly created service. Investigate the causality actor process that initiated the activity.Variations
Known Palo Alto service name with an uncommon image-path
Medium overridden
A Service with a known service name has an uncommon image-path. overridden
Known service name with an uncommon image-path in a suspicious folder
Medium overridden
A Service with a known service name has an uncommon image-path. overridden