Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters. tactic: TA0005 ✕

Download CSV Show ATT&CK heatmap
  • Office process spawned with suspicious command-line arguments Low 2 variations

    An Office process was executed with LOLBIN-like command-line arguments. This behavior is exhibited in the VBA-RunPE tool that executes executables from the memory of Word/Excel/PowerPoint.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Stealth (TA0005)
    ATT&CK techniques: Process Injection: Process Hollowing (T1055.012)
    Required data: XDR Agent
    Attacker's goals: Execute arbitrary code or run malicious applications undetected.
    Investigative actions: Check the file that spawns the office application and search for macros, formulas, or scripts.

    Variations

    Masqueraded office process spawned with suspicious command-line arguments

    Medium overridden

    An executable masquerading an office process was executed with LOLBIN-like command-line arguments. overridden

    PowerPoint process accesses a suspicious PPAM file

    Low overridden

    A PowerPoint process opened a PPAM file which might be used to execute malicious code. overridden