Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters.

Download CSV Show ATT&CK heatmap
  • Suspicious DotNet log file created Low 3 variations

    Payloads that use the DotNet framework may generate suspicious Microsoft DotNet log files.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Stealth (TA0005)
    ATT&CK techniques: Reflective Code Loading (T1620) Process Injection (T1055)
    Required data: XDR Agent with eXtended Threat Hunting (XTH)
    Attacker's goals: Run/Inject DotNet code in the context of a signed process.
    Investigative actions: Verify if the actor process is using DotNet in a valid way.* Check if a new application was recently installed on the host at the time of the alert.

    Variations

    DotNet log file created by svchost from 'Absolute software Corp' causality

    Informational overridden

    Causality 'Absolute software Corp' loads/injects into svchost and creates DotNet log files. overridden

    Suspicious DotNet log file created from an injected thread

    Low overridden

    Payloads that use the DotNet framework may generate suspicious Microsoft DotNet log files. overridden

    Suspicious DotNet log file created

    Low overridden

    Payloads that use the DotNet framework may generate suspicious Microsoft DotNet log files. overridden