Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. technique: T1027 ✕
Download CSV Show ATT&CK heatmapUnusual use of a 'SysInternals' tool Informational 3 variations
An attacker may be trying to avoid detection by using an obfuscated copy of SysInternals tools.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Stealth (TA0005)ATT&CK techniques: Obfuscated Files or Information (T1027)Required data: XDR Agent with eXtended Threat Hunting (XTH)Attacker's goals: Attackers may leverage SysInternals tools for lateral movement, credential access, or to delete recovery backups to cause impact.Investigative actions: Check if the file is familiar to the user, if not, investigate further the source of it.Variations
Unusual use of a 'SysInternals' tool by a process with an invalid or non-standard signature
High overridden
An attacker may be trying to avoid detection by using an obfuscated copy of SysInternals tools. overridden
Unusual use of a 'SysInternals' tool that can be used for offensive operations
High overridden
An attacker may be trying to avoid detection by using an obfuscated copy of SysInternals tools. overridden
A registry key related to SysInternals was modified by a known registry editor
Informational overridden
A registry key related to SysInternals was modified by a known registry editor to circumvent a EULA prompt. overridden