Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters. technique: T1648 ✕

Download CSV Show ATT&CK heatmap
  • Penetration testing tool activity attempt Informational Identity Analytics 1 variation

    A SaaS API was invoked by a penetration testing tool.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    2 Days
    ATT&CK tactics: Execution (TA0002)
    ATT&CK techniques: Serverless Execution (T1648)
    Required data: Office 365 Audit
    Attacker's goals: Usage of known tools and frameworks.
    Investigative actions: Check if there is an active PT test ongoing.

    Variations

    Penetration testing tool activity attempt

    Medium overridden

    A SaaS API was successfully invoked by a penetration testing tool. overridden