Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. tactic: TA0008 ✕ technique: T1021 ✕
Download CSV Show ATT&CK heatmapRare DCOM RPC activity Informational 1 variation
The endpoint performed abnormal DCOM RPC activity to a remote host.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Lateral Movement (TA0008)ATT&CK techniques: Remote Services: Distributed Component Object Model (T1021.003)Required data: Palo Alto Networks Firewall EAL Logs XDR Agent with eXtended Threat Hunting (XTH)Detector tags: NDR Lateral Movement AnalyticsAttacker's goals: Attackers may attempt to gain persistence or move laterally over the network by executing code on remote hosts using the DCOM RPC interface. The DCOM RPC interface is used to remotely invoke registered COM applications on remote hosts.Investigative actions: Review the action of the initiated COM application on the remote host. Correlate the RPC call from the source host and understand which software initiated it.* Verify that this isn't IT activity.Variations
Rare DCOM RPC activity
Low overridden
The endpoint performed abnormal DCOM RPC activity to a remote host. overridden