Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters.

Download CSV Show ATT&CK heatmap
  • Uncommon signed process execution by scheduled task Informational 3 variations

    An uncommon process was executed by a scheduled task.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Persistence (TA0003)
    ATT&CK techniques: Scheduled Task/Job (T1053)
    Required data: XDR Agent
    Detector tags: Scheduled tasks Analytics
    Attacker's goals: Attackers may attempt to gain persistence, privilege escalation or proxy execution on the endpoint using scheduled tasks.
    Investigative actions: Review the process executed by the schedule task. Investigate the specific scheduled task execution chain. Check if the vendor is known in the organization for creating scheduled tasks to execute his product.

    Variations

    Uncommon Microsoft signed process execution by scheduled task

    Informational overridden

    An uncommon process was executed by a scheduled task. overridden

    Uncommon signed process execution by scheduled task on a sensitive server

    Low overridden

    An uncommon process was executed by a scheduled task. overridden

    Rare signed process execution by scheduled task

    Low overridden

    A rare process was executed by a scheduled task. overridden