Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source
  • Uncommon file access over WebDAV Low 1 variation

    Uncommon file access over WebDAV.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Command and Control (TA0011)
    ATT&CK techniques: Application Layer Protocol: Web Protocols (T1071.001)
    Required data: XDR Agent with eXtended Threat Hunting (XTH)
    Attacker's goals: Threat actors may use the WebDAV to blend in existing network traffic.
    Investigative actions: Investigate the process {actor_process_image_name} which tried to access the remote file. Investigate the remote host {webdav_dst_from_file_event}.

    Variations

    High-risk file read over WebDAV by a LOLBIN process

    High overridden

    High-risk file read over WebDAV by a LOLBIN process. overridden