Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters. tactic: TA0002 ✕

Download CSV Show ATT&CK heatmap
  • Suspicious cloud user data modification attempt followed by VM restart Low Cloud

    Suspicious user data modification followed by VM restart, possibly an attempt to run altered startup scripts at boot.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    1 Hour
    Deduplication:
    1 Day
    ATT&CK tactics: Execution (TA0002)
    ATT&CK techniques: Cloud Administration Command (T1651)
    Required data: AWS Audit Log Gcp Audit Log
    Attacker's goals: Execute arbitrary code, establish persistence, or alter instance startup behavior through modified user data.
    Investigative actions: Review the identity who modified the instance user data. Inspect the user data script for malicious content.