Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. technique: T1546 ✕
Download CSV Show ATT&CK heatmapScreensaver process executed from Users or temporary folder Low 1 variation
An executable file with a screensaver extension was executed from the Users or temp folder. This is not a common behavior for screensavers and may indicate a malicious file disguised as a screensaver in the Users or temp folder. It is recommended to further investigate the execution flow for malicious indicators.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 6 Hours
ATT&CK tactics: Persistence (TA0003)ATT&CK techniques: Event Triggered Execution: Screensaver (T1546.002)Required data: XDR AgentAttacker's goals: Gain persistence by configuring a new screensaver.Investigative actions: Check whether the executing process (with the SCR extension) is benign and if this was a desired behavior as part of its normal execution flow.Variations
Screensaver process executed from Users or temporary folder by a scripting engine process
High overridden
An executable file with a screensaver extension was executed from the Users or temp folder by a scripting engine process. This is not a common behavior for screensavers and may indicate a malicious file disguised as a screensaver in the Users or temp folder. It is recommended to further investigate the execution flow for malicious indicators. overridden