Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters. technique: T1027 ✕

Download CSV Show ATT&CK heatmap
  • Unusual use of a 'SysInternals' tool Informational 3 variations

    An attacker may be trying to avoid detection by using an obfuscated copy of SysInternals tools.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Stealth (TA0005)
    ATT&CK techniques: Obfuscated Files or Information (T1027)
    Required data: XDR Agent with eXtended Threat Hunting (XTH)
    Attacker's goals: Attackers may leverage SysInternals tools for lateral movement, credential access, or to delete recovery backups to cause impact.
    Investigative actions: Check if the file is familiar to the user, if not, investigate further the source of it.

    Variations

    Unusual use of a 'SysInternals' tool by a process with an invalid or non-standard signature

    High overridden

    An attacker may be trying to avoid detection by using an obfuscated copy of SysInternals tools. overridden

    Unusual use of a 'SysInternals' tool that can be used for offensive operations

    High overridden

    An attacker may be trying to avoid detection by using an obfuscated copy of SysInternals tools. overridden

    A registry key related to SysInternals was modified by a known registry editor

    Informational overridden

    A registry key related to SysInternals was modified by a known registry editor to circumvent a EULA prompt. overridden