Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters. tactic: TA0004 ✕

Download CSV Show ATT&CK heatmap
  • LOLBIN process executed with a high integrity level Low 1 variation

    A process spawned a suspicious LOLBIN process with a higher/system integrity level. The LOLBIN process spawned with an uncommon command line. This may be an indication of malicious code execution to gain privileges.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Privilege Escalation (TA0004)
    ATT&CK techniques: Abuse Elevation Control Mechanism (T1548)
    Required data: XDR Agent
    Attacker's goals: An attacker may attempt to gain higher privileges.
    Investigative actions: Check whether the command line executed is benign or normal for the host and/or user performing it. Investigate the endpoint to determine if it's a legitimate process that is supposed to run with privileges.

    Variations

    LOLBIN process executed with a high integrity level by a web server process or CGO

    Medium overridden

    A process spawned a suspicious LOLBIN process with a higher/system integrity level by a web server process or CGO. The LOLBIN process spawned with an uncommon command line. This may be an indication of malicious code execution to gain privileges. overridden