Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters. technique: T1059 ✕

Download CSV Show ATT&CK heatmap
  • Unusual process executed by AWS Systems Manager Medium Cloud

    An unusual process was executed by the AWS Systems Manager agent. Adversaries may use the Systems Manager agent to execute malicious commands on an endpoint.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Execution (TA0002)
    ATT&CK techniques: Command and Scripting Interpreter (T1059)
    Required data: XDR Agent
    Detector tags: SSM Remote Management Analytics
    Attacker's goals: Adversaries may execute malicious code using legitimate cloud administration tools.
    Investigative actions: Verify if this is a legitimate script or command being run by an administrator using AWS Systems Manager.