Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters. technique: T1685 ✕

Download CSV Show ATT&CK heatmap
  • New addition to Windows Defender exclusion list Low 1 variation

    Windows Defender keeps the exclusion list in the registry, and any addition to it will cause it to ignore a process, path or file extension.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Hour
    ATT&CK tactics: Stealth (TA0005) Defense Impairment (TA0112)
    ATT&CK techniques: Hide Artifacts: File/Path Exclusions (T1564.012) Disable or Modify Tools (T1685)
    Required data: XDR Agent
    Attacker's goals: Gain code execution on the host and evade security controls.
    Investigative actions: Check whether the executing process is benign and if this was a desired behavior as part of its normal execution flow. Check the excluded object type (process, path or extension) and nature. Check if the excluded object is malicious.

    Variations

    New addition to Windows Defender exclusion list from an unsigned process

    Medium overridden

    Windows Defender keeps the exclusion list in the registry, and any addition to it will cause it to ignore a process, path or file extension. overridden