Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters. tactic: TA0008 ✕

Download CSV Show ATT&CK heatmap
  • Rare Remote Service (SVCCTL) RPC activity Informational 3 variations

    The endpoint performed abnormal RPC activity via Service Control Manager interface to a remote host.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Lateral Movement (TA0008)
    ATT&CK techniques: Remote Services (T1021)
    Required data: Palo Alto Networks Firewall EAL Logs XDR Agent with eXtended Threat Hunting (XTH)
    Detector tags: NDR Lateral Movement Analytics
    Attacker's goals: Attackers may attempt to gain persistence or move laterally over the network by executing code on remote hosts using services. The service control manager RPC interface is used to create and start services on a local or a remote host.
    Investigative actions: Review the action of services.exe on the remote host where possible. Correlate the RPC call from the source host and understand which software initiated it.* Verify that this isn't IT activity.

    Variations

    Rare remote service creation and initiation via Remote Service (SVCCTL) RPC interface

    Medium overridden

    The endpoint performed abnormal service creation and initiation via Remote Service (SVCCTL) RPC interface to a remote host. overridden

    Rare remote service change or creation via Remote Service (SVCCTL) RPC interface

    Medium overridden

    The endpoint performed abnormal service creation via Remote Service (SVCCTL) RPC interface to a remote host. overridden

    Rare Remote Service (SVCCTL) RPC activity

    Low overridden

    The endpoint performed abnormal RPC activity via Service Control Manager interface to a remote host. overridden