Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters. technique: T1204 ✕

Download CSV Show ATT&CK heatmap
  • Windows CGO, actor process and action module with anomalous characteristics Informational 1 variation

    Windows CGO, actor process and action module with anomalous characteristics.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Execution (TA0002)
    ATT&CK techniques: User Execution (T1204)
    Required data: XDR Agent
    Attacker's goals: Loading modules with anomalous characteristics that commonly appear in malicious activities.
    Investigative actions: Investigate the loaded image and check if it is malicious. Investigate the CGO process and actor process that loaded the module and check if they are malicious.

    Variations

    Windows CGO, actor process and action module with very anomalous characteristics

    Low overridden

    Windows CGO, actor process and action module with anomalous characteristics. overridden