Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source
  • Uncommon macOS process communication to a rare external host Informational 13 variations

    An uncommon process is connecting to an external host that is rarely accessed within the organization. This connection pattern is consistent with malicious activity such as command and control execution, malware download and so on.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Command and Control (TA0011)
    ATT&CK techniques: Application Layer Protocol (T1071)
    Required data: XDR Agent
    Detector tags: Abnormal Communication Analytics
    Attacker's goals: Establish a remote backdoor to issue instructions, deploy additional payloads, and maintain long-term persistence across the infected fleet.
    Investigative actions: Identify the process contacting the remote host and determine whether the traffic is malicious. Look for other endpoints on your network that are also contacting the suspicious host. Inspect the host or URL for suspicious indicators or its presence in malicious reputation lists.

    Variations

    Uncommon macOS process communication to a rare external host by security testing tool

    High overridden

    An uncommon process is connecting to an external host that is rarely accessed within the organization. This connection pattern is consistent with malicious activity such as command and control execution, malware download and so on. overridden

    Uncommon macOS process communication to a rare external host with a frequently abused TLD

    Medium overridden

    An uncommon process is connecting to an external host that is rarely accessed within the organization. This connection pattern is consistent with malicious activity such as command and control execution, malware download and so on. overridden

    Uncommon macOS process communication to a rare external host while using a CLI utility to establish a connection with a messaging service API

    Medium overridden

    An uncommon process is connecting to an external host that is rarely accessed within the organization. This connection pattern is consistent with malicious activity such as command and control execution, malware download and so on. overridden

    Uncommon macOS process communication to a rare external host involving a code sharing website by a high-risk actor

    Medium overridden

    An uncommon process is connecting to an external host that is rarely accessed within the organization. This connection pattern is consistent with malicious activity such as command and control execution, malware download and so on. overridden

    Uncommon macOS process communication to a rare external host involving a code sharing website

    Low overridden

    An uncommon process is connecting to an external host that is rarely accessed within the organization. This connection pattern is consistent with malicious activity such as command and control execution, malware download and so on. overridden

    Uncommon macOS process communication to a rare external host related to LOTTunnels

    Low overridden

    An uncommon process is connecting to an external host that is rarely accessed within the organization. This connection pattern is consistent with malicious activity such as command and control execution, malware download and so on. overridden

    Uncommon macOS process communication to a rare external host with a rare TLD

    Low overridden

    An uncommon process is connecting to an external host that is rarely accessed within the organization. This connection pattern is consistent with malicious activity such as command and control execution, malware download and so on. overridden

    Uncommon macOS process communication to a rare external host while using a CLI utility and piping to script

    Low overridden

    An uncommon process is connecting to an external host that is rarely accessed within the organization. This connection pattern is consistent with malicious activity such as command and control execution, malware download and so on. overridden

    Uncommon macOS process communication to a rare external host while using a CLI utility to download and change permission

    Low overridden

    An uncommon process is connecting to an external host that is rarely accessed within the organization. This connection pattern is consistent with malicious activity such as command and control execution, malware download and so on. overridden

    Uncommon macOS process communication to a rare external host while using a CLI utility running by an unsigned process

    Low overridden

    An uncommon process is connecting to an external host that is rarely accessed within the organization. This connection pattern is consistent with malicious activity such as command and control execution, malware download and so on. overridden

    Uncommon macOS process communication to a rare external host while using a CLI utility and saving data to a temporary folder

    Low overridden

    An uncommon process is connecting to an external host that is rarely accessed within the organization. This connection pattern is consistent with malicious activity such as command and control execution, malware download and so on. overridden

    Uncommon macOS process communication to a rare external host while using a CLI utility and downloading a script

    Low overridden

    An uncommon process is connecting to an external host that is rarely accessed within the organization. This connection pattern is consistent with malicious activity such as command and control execution, malware download and so on. overridden

    Uncommon macOS process communication to a rare external host while using a CLI utility

    Low overridden

    An uncommon process is connecting to an external host that is rarely accessed within the organization. This connection pattern is consistent with malicious activity such as command and control execution, malware download and so on. overridden