Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters. technique: T1098 ✕

Download CSV Show ATT&CK heatmap
  • Unusual user account enablement Informational Identity Analytics 1 variation

    A user enabled an account. This user does not usually enable user accounts.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Persistence (TA0003)
    ATT&CK techniques: Account Manipulation (T1098)
    Required data: Windows Event Collector XDR Agent with eXtended Threat Hunting (XTH)
    Attacker's goals: An attacker may enable a user account to gain persistence.
    Investigative actions: Investigate the associated enabling event. Check if the user is authorized to enable accounts. Confirm that the account enablement was expected. If the account enablement seems suspicious, address it accordingly by disabling the account again, forcing a password change, or monitoring its activity.

    Variations

    Unusual sensitive user account enablement

    Low overridden

    A user enabled a sensitive account. This user does not usually enable user accounts. overridden