Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source
  • VM Detection attempt on Linux Informational 2 variations

    A Process executed a command and/or accessed a file that can be used to detect VM environments.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Stealth (TA0005) Discovery (TA0007)
    ATT&CK techniques: Virtualization/Sandbox Evasion: System Checks (T1497.001)
    Required data: XDR Agent
    Attacker's goals: Avoid malware analysis by identifying execution from within sandboxes and virtual machines.
    Investigative actions: Review the process for additional malicious actions. Check for any additional alerts raised within the same context of the script.

    Variations

    VM Detection attempt on Linux with further reconnaissance commands

    Medium overridden

    A Process executed a command and/or accessed a file that can be used to detect VM environments. overridden

    VM Detection attempt on Linux using an unpopular technique

    Low overridden

    A Process executed a command and/or accessed a file that can be used to detect VM environments. overridden