Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters. technique: T1018 ✕

Download CSV Show ATT&CK heatmap
  • Multiple discovery-like commands Informational 3 variations

    The alerted process performed multiple consecutive discovery commands in a short time frame.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    10 Minutes
    Deduplication:
    1 Day
    ATT&CK tactics: Discovery (TA0007)
    ATT&CK techniques: Remote System Discovery (T1018) System Information Discovery (T1082) System Network Configuration Discovery (T1016) System Service Discovery (T1007)
    Required data: XDR Agent
    Attacker's goals: Collect information about the host, network and user configuration for lateral movement and privilege escalation.
    Investigative actions: Verify if the script or process initiating the discovery commands is benign. Verify that this isn't sanctioned IT activity. Look for other hosts executing similar commands.

    Variations

    Multiple discovery-like commands by web server process

    Low overridden

    The web server process performed multiple consecutive discovery commands in a short time frame. overridden

    Multiple discovery-like commands on a Linux host

    Informational overridden

    The alerted process performed multiple consecutive discovery commands in a short time frame. overridden

    Multiple discovery-like commands

    Informational overridden

    The alerted process performed multiple consecutive discovery commands in a short time frame. overridden