Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters.
Download CSV Show ATT&CK heatmapSuspicious DotNet log file created Low 3 variations
Payloads that use the DotNet framework may generate suspicious Microsoft DotNet log files.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Stealth (TA0005)ATT&CK techniques: Reflective Code Loading (T1620) Process Injection (T1055)Required data: XDR Agent with eXtended Threat Hunting (XTH)Attacker's goals: Run/Inject DotNet code in the context of a signed process.Investigative actions: Verify if the actor process is using DotNet in a valid way.* Check if a new application was recently installed on the host at the time of the alert.Variations
DotNet log file created by svchost from 'Absolute software Corp' causality
Informational overridden
Causality 'Absolute software Corp' loads/injects into svchost and creates DotNet log files. overridden
Suspicious DotNet log file created from an injected thread
Low overridden
Payloads that use the DotNet framework may generate suspicious Microsoft DotNet log files. overridden
Suspicious DotNet log file created
Low overridden
Payloads that use the DotNet framework may generate suspicious Microsoft DotNet log files. overridden