Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters. tactic: TA0003 ✕

Download CSV Show ATT&CK heatmap
  • Suspicious Udev driver rule execution manipulation Low 1 variation

    Udev driver rule was modified with unusual pattern, might be used by adversaries to backdoor existing drivers.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Persistence (TA0003) Privilege Escalation (TA0004)
    ATT&CK techniques: Boot or Logon Autostart Execution: Kernel Modules and Extensions (T1547.006)
    Required data: XDR Agent with eXtended Threat Hunting (XTH)
    Attacker's goals: Adversaries can use this technique to execute arbitrary commands once the machine boots.
    Investigative actions: Check if the action was done using an automation service. Check the rule modification content and look for any suspicious payloads. Check if there are any other suspicious activities originated from the same machine/executing user.

    Variations

    Unusual Udev driver rule execution manipulation

    Low overridden

    Udev driver rule was modified with unusual pattern, might be used by adversaries to backdoor existing drivers. overridden