Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters. tactic: TA0007 ✕

Download CSV Show ATT&CK heatmap
  • SCCM log files enumeration Informational Identity Analytics 1 variation

    Multiple local SCCM logs were accessed within a short period of time.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    1 Hour
    Deduplication:
    1 Day
    ATT&CK tactics: Discovery (TA0007)
    ATT&CK techniques: Log Enumeration (T1654)
    Required data: XDR Agent with eXtended Threat Hunting (XTH)
    Detector tags: Microsoft SCCM Analytics
    Attacker's goals: Enumerate data about the SCCM configuration, infrastructure and deployments.
    Investigative actions: Check suspicious network connections from the process or host. Check if the user account that initiated the enumeration is supposed to access these files.

    Variations

    Suspicious SCCM log files enumeration

    Low overridden

    Multiple local SCCM logs were abnormally accessed within a short period of time. overridden