Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source
  • Unicode RTL Override Character High

    An attacker may use a special right-to-left (RTL) override character to trick users into executing malicious files that look like benign file types.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Stealth (TA0005)
    ATT&CK techniques: Obfuscated Files or Information (T1027)
    Required data: XDR Agent
    Attacker's goals: Trick users into executing malicious files by making their file types seem benign.
    Investigative actions: Investigate the executed process. There is no reason for benign files to contain the Unicode right-to-left override character in their name.