Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source
  • Modification of the AD FS IdentityServer configuration file Informational Identity Analytics 1 variation

    The AD FS service configuration file was modified.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Stealth (TA0005)
    ATT&CK techniques: Hijack Execution Flow (T1574)
    Required data: XDR Agent with eXtended Threat Hunting (XTH)
    Detector tags: Active Directory Federation Services Analytics
    Attacker's goals: The attacker's goal is to establish a persistent, high-privilege backdoor by forcing the service to load a malicious configuration that enables remote code execution and the bypass of security controls like MFA.
    Investigative actions: Check if the AD FS service was stopped or restarted around the time of modification. Investigate the process and user that performed the write operation for signs of compromise.

    Variations

    Suspicious Modification of the AD FS IdentityServer configuration file

    Low overridden

    The AD FS service configuration file was modified. overridden