Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters. technique: T1016 ✕

Download CSV Show ATT&CK heatmap
  • Multiple discovery commands on a Linux host by the same process Informational 2 variations

    The alerted process performed multiple consecutive discovery commands in a short timeframe.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    10 Minutes
    Deduplication:
    1 Day
    ATT&CK tactics: Discovery (TA0007)
    ATT&CK techniques: Remote System Discovery (T1018) System Information Discovery (T1082) System Network Configuration Discovery (T1016) System Service Discovery (T1007)
    Required data: XDR Agent
    Attacker's goals: Collect information about the host, network and user configuration for lateral movement and privilege escalation.
    Investigative actions: Verify if the script or process initiating the discovery commands is benign. Verify that this isn't sanctioned IT activity. Look for other hosts executing similar commands.

    Variations

    Multiple discovery commands on a Linux host by the same process

    Medium overridden

    The alerted process performed multiple consecutive discovery commands in a short timeframe. overridden

    Multiple discovery commands on a Linux host by the same process

    Low overridden

    The alerted process performed multiple consecutive discovery commands in a short timeframe. overridden