Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters.
Download CSV Show ATT&CK heatmapUncommon driver loaded Low 3 variations
An uncommon driver loaded which may be an attempt to kill the EDR or install rootkit.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Stealth (TA0005)ATT&CK techniques: Rootkit (T1014)Required data: XDR AgentAttacker's goals: Install rootkit to gain kernel-level to gain full control over the machine or disable security products.Investigative actions: Investigate which process created the driver or how it has been loaded.Variations
Uncommon driver loaded by a Web server process
High overridden
An uncommon driver loaded which may be an attempt to kill the EDR or install rootkit by a Web server process. overridden
Globally rare and unsigned driver loaded
Medium overridden
Globally rare and unsigned driver loaded. overridden
Uncommon driver with a globally rare vendor loaded as a service
Medium overridden
An uncommon driver loaded which may be an attempt to kill the EDR or install rootkit. overridden