Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters.

Download CSV Show ATT&CK heatmap
  • Suspicious docker image download from an unusual repository Informational 2 variations

    The agent has pulled a docker image from a repository for the first time.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Execution (TA0002)
    ATT&CK techniques: User Execution: Malicious Image (T1204.003)
    Required data: XDR Agent
    Detector tags: Kubernetes - AGENT, Containers
    Attacker's goals: Adversaries may rely on a user running a malicious image to facilitate execution.
    Investigative actions: Scan the docker image that was pulled. Check the repository designation. Check on which other agents the docker image is being used.

    Variations

    Suspicious docker image download from an unrecognized registry

    Low overridden

    The agent has pulled a docker image from a registry that has never been used in the organization. overridden

    Suspicious docker image download from an unrecognized repository

    Low overridden

    The agent has pulled a docker image from a repository that has never been used in the organization. overridden