Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. technique: T1027 ✕
Download CSV Show ATT&CK heatmapPossible binary padding using dd Informational
A suspicious dd command ran and added data to a binary. This may indicate binary padding to change the hash of a file.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Hour
ATT&CK tactics: Stealth (TA0005)ATT&CK techniques: Obfuscated Files or Information: Binary Padding (T1027.001)Required data: XDR AgentAttacker's goals: An adversary may use binary padding to avoid hash-based blacklists and static antivirus signatures.Investigative actions: Check the padded file and try to understand the impact of padding this specific binary.