Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters.

Download CSV Show ATT&CK heatmap
  • Remote command execution via wmic.exe Low 1 variation

    Remote command execution using the Windows Management Instrumentation command-line tool.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Execution (TA0002)
    ATT&CK techniques: Windows Management Instrumentation (T1047)
    Required data: XDR Agent
    Attacker's goals: The attacker is expanding his reach into your network by executing commands on a remote endpoint.
    Investigative actions: Examine Alert Details > Overview to identify the source endpoint, process running the command execution, process owner, and execution destination.

    Variations

    Remote command execution via wmic.exe

    Medium overridden

    Remote command execution using the Windows Management Instrumentation command-line tool. overridden