Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source
  • Uncommon driver loaded Low 3 variations

    An uncommon driver loaded which may be an attempt to kill the EDR or install rootkit.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Stealth (TA0005)
    ATT&CK techniques: Rootkit (T1014)
    Required data: XDR Agent
    Attacker's goals: Install rootkit to gain kernel-level to gain full control over the machine or disable security products.
    Investigative actions: Investigate which process created the driver or how it has been loaded.

    Variations

    Uncommon driver loaded by a Web server process

    High overridden

    An uncommon driver loaded which may be an attempt to kill the EDR or install rootkit by a Web server process. overridden

    Globally rare and unsigned driver loaded

    Medium overridden

    Globally rare and unsigned driver loaded. overridden

    Uncommon driver with a globally rare vendor loaded as a service

    Medium overridden

    An uncommon driver loaded which may be an attempt to kill the EDR or install rootkit. overridden