Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters. tactic: TA0002 ✕

Download CSV Show ATT&CK heatmap
  • Windows CGO, actor and action processes with anomalous characteristics Informational 1 variation

    Windows CGO, actor and action processes with anomalous characteristics.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Execution (TA0002)
    ATT&CK techniques: User Execution (T1204)
    Required data: XDR Agent
    Detector tags: Process Anomaly Analytics
    Attacker's goals: Processes anomalous characteristics which commonly appear in malicious activities.
    Investigative actions: Investigate the executed process image and check if it is malicious. Investigate the CGO and actor processes that executed the process and check if they are malicious.

    Variations

    Windows CGO, actor and action processes with highly anomalous characteristics

    Low overridden

    Windows CGO, actor and action processes with anomalous characteristics. overridden