Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source
  • The Linux system firewall was disabled Low

    The system firewall was disabled.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    10 Minutes
    ATT&CK tactics: Defense Impairment (TA0112)
    ATT&CK techniques: Disable or Modify System Firewall (T1686)
    Required data: XDR Agent
    Attacker's goals: Exfiltrate data or move laterally in the organization.
    Investigative actions: Examine the command to understand which ip or port were affected. Check the communication allowed by the created firewall rule.