Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. tactic: TA0002 ✕ technique: T1204 ✕
Download CSV Show ATT&CK heatmapWindows CGO, actor process and action module with anomalous characteristics Informational 1 variation
Windows CGO, actor process and action module with anomalous characteristics.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Execution (TA0002)ATT&CK techniques: User Execution (T1204)Required data: XDR AgentAttacker's goals: Loading modules with anomalous characteristics that commonly appear in malicious activities.Investigative actions: Investigate the loaded image and check if it is malicious. Investigate the CGO process and actor process that loaded the module and check if they are malicious.Variations
Windows CGO, actor process and action module with very anomalous characteristics
Low overridden
Windows CGO, actor process and action module with anomalous characteristics. overridden