Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters.

Download CSV Show ATT&CK heatmap
  • Uncommon creation or access operation of sensitive shadow copy Low 2 variations

    An uncommon creation or access of a sensitive Shadow Copy volume path.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Credential Access (TA0006)
    ATT&CK techniques: OS Credential Dumping (T1003)
    Required data: XDR Agent with eXtended Threat Hunting (XTH)
    Attacker's goals: Attackers may try to copy sensitive data or dump OS credentials from the host file system by using Shadow Copy volume utilities.
    Investigative actions: Verify if the shadow copy operation is part of an IT activity. Look for other hosts performing the same shadow copy event with similar causality process behavior.* Inspect the causality process and its characteristics as they appear on other hosts.

    Variations

    Uncommon creation or access operation of sensitive shadow copy by a remote actor

    Low overridden

    An uncommon creation or access of a sensitive Shadow Copy volume path. overridden

    Uncommon creation or access operation of sensitive shadow copy by a high-risk process

    High overridden

    An uncommon creation or access of a sensitive Shadow Copy volume path by a high-risk process. overridden