Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. tactic: TA0004 ✕
Download CSV Show ATT&CK heatmapLOLBIN process executed with a high integrity level Low 1 variation
A process spawned a suspicious LOLBIN process with a higher/system integrity level. The LOLBIN process spawned with an uncommon command line. This may be an indication of malicious code execution to gain privileges.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Privilege Escalation (TA0004)ATT&CK techniques: Abuse Elevation Control Mechanism (T1548)Required data: XDR AgentAttacker's goals: An attacker may attempt to gain higher privileges.Investigative actions: Check whether the command line executed is benign or normal for the host and/or user performing it. Investigate the endpoint to determine if it's a legitimate process that is supposed to run with privileges.Variations
LOLBIN process executed with a high integrity level by a web server process or CGO
Medium overridden
A process spawned a suspicious LOLBIN process with a higher/system integrity level by a web server process or CGO. The LOLBIN process spawned with an uncommon command line. This may be an indication of malicious code execution to gain privileges. overridden