Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters. tactic: TA0008 ✕

Download CSV Show ATT&CK heatmap
  • Remote DCOM command execution Low 4 variations

    A remotely triggered DCOM initiated a command execution by a host that rarely executes processes using DCOM to other remote hosts.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Lateral Movement (TA0008)
    ATT&CK techniques: Remote Services: Distributed Component Object Model (T1021.003)
    Required data: XDR Agent
    Detector tags: Impacket Analytics
    Attacker's goals: Perform lateral movement to new hosts to expand the foothold within a network.
    Investigative actions: Investigate the processes being spawned on the host for malicious activities. Correlate the DCOM call from the source host and understand which software initiated it.

    Variations

    Remote suspicious DCOM-MMC20.Application command execution

    High overridden

    A remotely triggered suspicious DCOM-MMC20.Application initiated a command execution by a host that rarely executes processes using DCOM to other remote hosts. overridden

    Remote suspicious DCOM-Excel.Application command execution

    High overridden

    A remotely triggered suspicious DCOM-Excel.Application initiated a command execution by a host that rarely executes processes using DCOM to other remote hosts. overridden

    Remote suspicious DCOM-Outlook.Application command execution

    High overridden

    A remotely triggered suspicious DCOM-Outlook.Application initiated a command execution by a host that rarely executes processes using DCOM to other remote hosts. overridden

    Remote suspicious DCOM command execution

    Medium overridden

    A remotely triggered suspicious DCOM initiated a command execution by a host that rarely executes processes using DCOM to other remote hosts. overridden