Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. tactic: TA0002 ✕
Download CSV Show ATT&CK heatmapWindows CGO, actor and action processes with anomalous characteristics Informational 1 variation
Windows CGO, actor and action processes with anomalous characteristics.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Execution (TA0002)ATT&CK techniques: User Execution (T1204)Required data: XDR AgentDetector tags: Process Anomaly AnalyticsAttacker's goals: Processes anomalous characteristics which commonly appear in malicious activities.Investigative actions: Investigate the executed process image and check if it is malicious. Investigate the CGO and actor processes that executed the process and check if they are malicious.Variations
Windows CGO, actor and action processes with highly anomalous characteristics
Low overridden
Windows CGO, actor and action processes with anomalous characteristics. overridden