Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters. tactic: TA0007 ✕

Download CSV Show ATT&CK heatmap
  • Uncommon routing table listing via route.exe Low

    The route.exe command is used to display and modify entries in the local IP routing table. Adversaries may attempt to use the command to discover remote systems they could compromise.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Hour
    ATT&CK tactics: Discovery (TA0007)
    ATT&CK techniques: System Network Configuration Discovery (T1016)
    Required data: XDR Agent
    Attacker's goals: Attackers can attempt to use the command to discover remote systems they could compromise.
    Investigative actions: Check whether the command line executed is benign or normal for the host and/or user performing it (e.g. an IT script).