Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters.
Download CSV Show ATT&CK heatmapUncommon routing table listing via route.exe Low
The route.exe command is used to display and modify entries in the local IP routing table. Adversaries may attempt to use the command to discover remote systems they could compromise.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Hour
ATT&CK tactics: Discovery (TA0007)ATT&CK techniques: System Network Configuration Discovery (T1016)Required data: XDR AgentAttacker's goals: Attackers can attempt to use the command to discover remote systems they could compromise.Investigative actions: Check whether the command line executed is benign or normal for the host and/or user performing it (e.g. an IT script).