Analytics Alerts
Browse the Cortex analytics alert reference.
1300 alerts match the current filters.
Download CSV Show ATT&CK heatmapRare process created an SSH session to an uncommon cloud resource Low
A rare process created an SSH session to an uncommon cloud resource.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Command and Control (TA0011)ATT&CK techniques: Application Layer Protocol (T1071)Required data: Palo Alto Networks Firewall traffic Logs XDR Agent Third-Party FirewallsDetector tags: EDR Windows C2 AnalyticsAttacker's goals: Attackers may use SSH or any similar utility as a Command and Control (C2) channel or to exfiltrate data to a remote host.Investigative actions: Investigate the actor process and its causality. Review the remote cloud asset, is it managed by the organization or a partner? Search for processes or files that were accessed by this SSH instance.Rare process created an SSH session to an uncommon external host Low 3 variations
Rare process created an SSH session to an uncommon external host.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Command and Control (TA0011)ATT&CK techniques: Application Layer Protocol (T1071)Required data: Palo Alto Networks Firewall traffic Logs XDR Agent Third-Party FirewallsDetector tags: EDR Windows C2 AnalyticsAttacker's goals: Attackers may use SSH or any similar utility to as a Command and Control (C2) channel or to exfiltrate data to a remote host.Investigative actions: Investigate the actor process and its causality. Review the external IP/domain using known intelligence tools. Search for processes or files that were accessed by this SSH instance.Variations
Rare process created an SSH session to a domain with an uncommon TLD
Medium overridden
Rare process created an SSH session to a domain with an uncommon TLD. overridden
Rare process created an SSH session to an globally uncommon external host
Low overridden
Rare process created an SSH session to an globally uncommon external host. overridden
Rare process created an SSH session to an external host
Informational overridden
Rare process created an SSH session to an external host. overridden
Rare process executed by an AppleScript Low
An uncommon process has been executed by the AppleScript interpreter process.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Execution (TA0002)ATT&CK techniques: Command and Scripting Interpreter: AppleScript (T1059.002)Required data: XDR AgentDetector tags: AppleScript AnalyticsAttacker's goals: Use the AppleScript interpreter to execute a second-stage payload.Investigative actions: Analyze the AppleScript and executed process to determine whether they perform any malicious or suspicious actions. Check the events generated by the process or its children for potential malicious behavior. Check whether the AppleScript was executed in an unusual way.Rare process execution by user Informational Identity Analytics
An unusual process was executed by a user. This may be indicative of a compromised account.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 30 Days
ATT&CK tactics: Execution (TA0002)ATT&CK techniques: User Execution (T1204)Required data: XDR AgentAttacker's goals: Unusual processes may be executed for various purposes, including exfiltration, lateral movement, etc.Investigative actions: Investigate the process that was executed to determine if it was used for legitimate purposes or malicious activity.Rare process execution in organization Informational Identity Analytics
An unusual process was executed in the organization. This may be indicative of a compromised account.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 30 Days
ATT&CK tactics: Execution (TA0002)ATT&CK techniques: User Execution (T1204)Required data: XDR AgentAttacker's goals: Unusual processes may be executed for various purposes, including exfiltration, lateral movement, etc.Investigative actions: Investigate the process that was executed to determine if it was used for legitimate purposes or malicious activity.Rare process spawned by srvany.exe Informational
Unusual process spawned by srvany.exe, which allows applications to run as services with system privileges, this might be an indication of malicious local or remote code execution.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Hour
ATT&CK tactics: Execution (TA0002)ATT&CK techniques: System Services: Service Execution (T1569.002)Required data: XDR AgentAttacker's goals: Execute malware on the host in a manner that doesn't leave event logs within the system.Investigative actions: Validate if the binary that srvany.exe executed is malicious. Track down the source of the srvany.exe binary and the executed process. Validate if this is a legitimate software installed by IT.Rare process with VNC server capabilities started Low
A rare process with VNC server capabilities was started.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Command and Control (TA0011) Lateral Movement (TA0008)ATT&CK techniques: Remote Access Tools (T1219) Remote Services: VNC (T1021.005)Required data: XDR AgentAttacker's goals: Accessing a remote machine with full interactive graphic interface capabilities.Investigative actions: Check if the product usage is approved. Check if it was executed remotely or locally.Rare scheduled task created Informational 4 variations
A new rare scheduled task was created with a rare path and a rare command line.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Persistence (TA0003)ATT&CK techniques: Scheduled Task/Job (T1053)Required data: XDR Agent with eXtended Threat Hunting (XTH)Detector tags: Impacket Analytics, Scheduled tasks AnalyticsAttacker's goals: Attackers may attempt to gain persistence on the endpoint using scheduled task.Investigative actions: Review the action of the created scheduled task. Investigate the execution chain of the process creating the scheduled task.Variations
Rare scheduled task created by an injected actor
High overridden
A new rare scheduled task was created by an injected actor with a rare path and a rare command line. overridden
Uncommon remote scheduled task created
Medium overridden
A new uncommon remote scheduled task was created with a rare path and a rare command line. overridden
Uncommon local scheduled task created
Low overridden
A new uncommon local scheduled task was created with a rare path and a rare command line. overridden
Highly rare scheduled task created
Low overridden
A new rare scheduled task was created with an highly rare path and a rare command line. overridden
Rare security product signed executable executed in the network Low
Attackers may attempt to install a security product with a known vulnerability to bypass security features.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Defense Evasion (TA0005)ATT&CK techniques: Exploitation for Defense Evasion (T1211)Required data: XDR AgentAttacker's goals: Adversaries may exploit the application vulnerability to bypass security features.Investigative actions: Check if the security product was installed by a legitimate user and intentionally.Rare service DLL was added to the registry Low 2 variations
A service was added as a dll, which will be executed by svchost.exe. This is a stealthy technique attackers use to persist their malware.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Defense Evasion (TA0005) Persistence (TA0003)ATT&CK techniques: Masquerading: Masquerade Task or Service (T1036.004) Create or Modify System Process: Windows Service (T1543.003)Required data: XDR Agent with eXtended Threat Hunting (XTH)Detector tags: Malicious Service AnalyticsAttacker's goals: Masquerade execution on the host using a benign Windows process and achieve persistence.Investigative actions: Investigate the suspicious DLL and check for malicious content. Go to the service registry key and investigate it to find the associated executable that runs the service. Check whether the executing process is benign and if this was a desired behavior as part of its normal execution flow.Variations
Rare service DLL was added to the registry from an injected thread
Medium overridden
A service was added as a dll, which will be executed by svchost.exe. This is a stealthy technique attackers use to persist their malware. overridden
Rare service DLL was added to the registry from a rare unsigned actor process
High overridden
A service was added as a dll, which will be executed by svchost.exe. This is a stealthy technique attackers use to persist their malware. overridden
Rare signature signed executable executed in the network Informational 4 variations
Attackers may use signed executables by less known vendors to bypass security features.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 30 Days
ATT&CK tactics: Defense Evasion (TA0005)ATT&CK techniques: Subvert Trust Controls: Code Signing (T1553.002)Required data: XDR AgentAttacker's goals: Adversaries may use signed binaries to bypass security features.Investigative actions: Check if this is legitimate software installed by a legitimate user and intentionally.Variations
Rare signature signed forensic tool remotely executed in the network
Medium overridden
Attackers may use signed executables by less known vendors to bypass security features. overridden
Rare signature signed forensic tool executed in the network
Low overridden
Attackers may use signed executables by less known vendors to bypass security features. overridden
Rare signature signed executable extracted from an internet-downloaded archive and executed in the network
Low overridden
Attackers may use signed executables by less known vendors to bypass security features. overridden
Rare signature signed executable downloaded from an uncommon source and executed in the network
Low overridden
Attackers may use signed executables by less known vendors to bypass security features. overridden
Rare unsigned process execution by scheduled task Low 3 variations
Rare and unsigned process was executed by a scheduled task.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Persistence (TA0003)ATT&CK techniques: Scheduled Task/Job (T1053)Required data: XDR AgentDetector tags: Scheduled tasks AnalyticsAttacker's goals: Attackers may attempt to gain persistence on the endpoint using scheduled tasks.Investigative actions: Review the process executed by the schedule task. Investigate the specific scheduled task execution chain.Variations
Uncommon unsigned process execution by scheduled task
Informational overridden
Uncommon and unsigned process was executed by a scheduled task. overridden
Rare unsigned process execution with high integrity level by scheduled task
Medium overridden
Rare and unsigned process was execution with high integrity level by a scheduled task. overridden
Rare unsigned process execution by scheduled task on a sensitive server
Medium overridden
Rare and unsigned process was executed by a scheduled task. overridden
Rarely seen sender address in the organization Informational Email
An email was received from a sender that has not been observed in the organization in the last 30 days.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Reconnaissance (TA0043) Initial Access (TA0001)ATT&CK techniques: Phishing for Information (T1598) Phishing (T1566)Required data: Microsoft 365 EmailsAttacker's goals: Aim to steal sensitive information Trick recipients into downloading harmful payloads Aim to gain unauthorized access to the organization's systems.Investigative actions: Check the email address for any unusual spellings, missing letters, or unknown domains. If the message contains attachments or links, scrutinize them for any suspicious indications. Monitor further actions taken, such as file downloads or access to potentially malicious links.Rarely seen sender domain in the organization Informational Email
An email was received from a domain that has not been observed in the organization in the last 30 days.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Reconnaissance (TA0043) Initial Access (TA0001)ATT&CK techniques: Phishing for Information (T1598) Phishing (T1566)Required data: Microsoft 365 EmailsAttacker's goals: Aim to steal sensitive information Trick recipients into downloading harmful payloads Aim to gain unauthorized access to the organization's systems.Investigative actions: Check the email address for any unusual spellings, missing letters, or unknown domains. If the message contains attachments or links, scrutinize them for any suspicious indications. Monitor further actions taken, such as file downloads or access to potentially malicious links.Reading bash command history file Low
Attackers may access the bash history file to glean cleartext usernames and passwords that were entered on the command line.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Credential Access (TA0006)ATT&CK techniques: Unsecured Credentials: Shell History (T1552.003)Required data: XDR AgentAttacker's goals: Adversaries may search the bash history file to search for insecurely stored credentials.Investigative actions: Investigate the process activities and use of the extracted credentials.Recurring access to rare IP Low
The endpoint is periodically accessing an external fixed-IP address that its peers rarely use. Access to this external IP address has occurred repeatedly over many days. This connection pattern is consistent with malware connecting to its command and control server for updates and operating instructions.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 21 Days
ATT&CK tactics: Command and Control (TA0011)ATT&CK techniques: Non-Application Layer Protocol (T1095)Required data: Palo Alto Networks Firewall traffic Logs XDR Agent Third-Party FirewallsAttacker's goals: Communicate with malicious code running on your network enabling further access to the endpoint and network, performing software updates on the endpoint, or for taking inventory of infected machines.Investigative actions: Identify if the IP address belongs to a reputable organization or an asset used in a public cloud. Identify if the source of the traffic is malware. If the source of the traffic is a malicious file, Cortex XDR Analytics also raises a malware alert for the file on the endpoint. Malware may contact legitimate IP addresses, therefore check for unusual apps used or unusual ports or volumes accessed. View all related traffic generated by the suspicious process to understand the purpose. Look for other endpoints on your network that are also contacting the suspicious IP address. Examine file-system operations performed by the process to look for potential artifacts on infected endpoints.Recurring access to rare domain Low 1 variation
The endpoint is periodically connecting to an external domain (categorized as malware) that it and its peers rarely use. Access to this domain has occurred repeatedly over multiple days. This connection pattern is consistent with malware connecting to its command and control server for updates and operating instructions.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Command and Control (TA0011)ATT&CK techniques: Application Layer Protocol (T1071)Required data: Palo Alto Networks Firewall EAL Logs Palo Alto Networks Firewall threat Logs XDR Agent Third-Party FirewallsAttacker's goals: Communicate with malware running on your network to control malware activities, perform software updates on the malware, or to take inventory of infected machines.Investigative actions: Identify the process/user contacting the remote domain and determine whether the traffic is malicious. Look for other endpoints on your network that are also periodically contacting the suspicious domain.Variations
Recurring access to rare domain
Low overridden
The endpoint is periodically connecting to an external domain (categorized as command-and-control) that it and its peers rarely use. Access to this domain has occurred repeatedly over multiple days. This connection pattern is consistent with malware connecting to its command and control server for updates and operating instructions. overridden
Recurring rare domain access from an unsigned process Low 2 variations
An unsigned process is periodically connecting to an external domain that it and its peers rarely use. Access to this domain has occurred repeatedly over multiple days. This connection pattern is consistent with malware connecting to its command and control server for updates and operating instructions.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 14 Days
ATT&CK tactics: Command and Control (TA0011)ATT&CK techniques: Application Layer Protocol (T1071)Required data: XDR AgentAttacker's goals: Communicate with malware running on your network to control malware activities, perform software updates on the malware, or to take inventory of infected machines.Investigative actions: Identify the process contacting the remote domain and determine whether the traffic is malicious. Look for other endpoints on your network that are also periodically contacting the suspicious domain. Inspect the domain or URL for suspicious indicators or its presence in malicious reputation lists.Variations
Recurring rare domain access from an uncommon unsigned process
Medium overridden
An unsigned process is periodically connecting to an external domain that it and its peers rarely use. Access to this domain has occurred repeatedly over multiple days. This connection pattern is consistent with malware connecting to its command and control server for updates and operating instructions. overridden
Recurring access to a rare domain associated with known threats
Medium overridden
An unsigned process is periodically connecting to an external domain that it and its peers rarely use. Access to this domain has occurred repeatedly over multiple days. This connection pattern is consistent with malware connecting to its command and control server for updates and operating instructions. overridden
Recurring rare domain access to dynamic DNS domain Low
The endpoint is periodically connecting to an external domain that it and its peers rarely use. Access to this domain has occurred repeatedly over multiple days. This connection pattern is consistent with malware connecting to its command and control server for updates and operating instructions.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 14 Days
ATT&CK tactics: Command and Control (TA0011)ATT&CK techniques: Application Layer Protocol (T1071)Required data: Palo Alto Networks Firewall traffic Logs XDR Agent Third-Party FirewallsAttacker's goals: Communicate with malware running on your network to control malware activities, perform software updates on the malware, or to take inventory of infected machines.Investigative actions: Identify the process/user contacting the remote domain and determine whether the traffic is malicious. Look for other endpoints on your network that are also periodically contacting the suspicious domain.Registration of Uncommon .NET Services and/or Assemblies Informational
Regasm.exe and regsvcs.exe are used to register .NET COM assemblies, which are typically located in specific paths, attackers might leverage that to execute code within a Microsoft signed binary.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Hour
ATT&CK tactics: Defense Evasion (TA0005)ATT&CK techniques: System Binary Proxy Execution: Regsvcs/Regasm (T1218.009)Required data: XDR AgentAttacker's goals: Load untrusted code into a trusted Microsoft context to evade detection.Investigative actions: Verify if the loaded dll is known to be malicious. Track down which process dropped the library being loaded. Validate if the actions being done by the regasm.exe process are malicious.Remote DCOM command execution Low 4 variations
A remotely triggered DCOM initiated a command execution by a host that rarely executes processes using DCOM to other remote hosts.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Lateral Movement (TA0008)ATT&CK techniques: Remote Services: Distributed Component Object Model (T1021.003)Required data: XDR AgentDetector tags: Impacket AnalyticsAttacker's goals: Perform lateral movement to new hosts to expand the foothold within a network.Investigative actions: Investigate the processes being spawned on the host for malicious activities. Correlate the DCOM call from the source host and understand which software initiated it.Variations
Remote suspicious DCOM-MMC20.Application command execution
High overridden
A remotely triggered suspicious DCOM-MMC20.Application initiated a command execution by a host that rarely executes processes using DCOM to other remote hosts. overridden
Remote suspicious DCOM-Excel.Application command execution
High overridden
A remotely triggered suspicious DCOM-Excel.Application initiated a command execution by a host that rarely executes processes using DCOM to other remote hosts. overridden
Remote suspicious DCOM-Outlook.Application command execution
High overridden
A remotely triggered suspicious DCOM-Outlook.Application initiated a command execution by a host that rarely executes processes using DCOM to other remote hosts. overridden
Remote suspicious DCOM command execution
Medium overridden
A remotely triggered suspicious DCOM initiated a command execution by a host that rarely executes processes using DCOM to other remote hosts. overridden
Remote PsExec-like command execution Informational 5 variations
A remotely triggered service initiated a command execution in a PsExec-like manner by a host that rarely triggers services to other remote hosts.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Lateral Movement (TA0008) Execution (TA0002)ATT&CK techniques: Remote Services (T1021) System Services: Service Execution (T1569.002) Lateral Tool Transfer (T1570)Required data: XDR AgentDetector tags: Impacket AnalyticsAttacker's goals: Perform lateral movement to new hosts to expand the foothold within a network.Investigative actions: Investigate the processes being spawned on the host for malicious activities. Correlate the RPC call from the source host and understand which software initiated it.Variations
Remote PsExec-like LOLBIN command execution from an unsigned non-standard PsExec service
High overridden
A remotely triggered service initiated a command execution in a PsExec-like manner by a host that rarely triggers services to other remote hosts. overridden
Remote PsExec-like LOLBIN command execution from a signed non-standard PsExec service
Medium overridden
A remotely triggered service initiated a command execution in a PsExec-like manner by a host that rarely triggers services to other remote hosts. overridden
Remote PsExec-like command execution from an unsigned non-standard PsExec service
Medium overridden
A remotely triggered service initiated a command execution in a PsExec-like manner by a host that rarely triggers services to other remote hosts. overridden
Remote PsExec-like command execution from a signed non-standard PsExec service
Low overridden
A remotely triggered service initiated a command execution in a PsExec-like manner by a host that rarely triggers services to other remote hosts. overridden
Remote PsExec command execution
Low overridden
A remotely triggered service initiated a command execution in a PsExec-like manner by a host that rarely triggers services to other remote hosts. overridden
Remote WMI process execution Medium 1 variation
A host that rarely initiates WMI to other remote hosts triggered a remote process execution by using WMI RPC.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 3 Days
ATT&CK tactics: Lateral Movement (TA0008)ATT&CK techniques: Remote Services (T1021) Remote Services: Windows Remote Management (T1021.006)Required data: XDR AgentDetector tags: Impacket AnalyticsAttacker's goals: Perform lateral movement to new hosts to expand the foothold within a network.Investigative actions: Investigate the processes being spawned on the host for malicious activities. Correlate the RPC call from the source host and understand which process or software initiated it.Variations
Suspicious remote WMI process execution
High overridden
A host that rarely initiates WMI to other remote hosts triggered a suspicious remote process execution by using WMI RPC. overridden
Remote account enumeration Informational Identity Analytics 2 variations
Multiple non-existing accounts failed to remotely log in to a host in a short period of time. This may indicate an attacker is trying to remotely enumerate accounts.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- 10 Minutes
- Deduplication:
- 1 Day
ATT&CK tactics: Discovery (TA0007) Credential Access (TA0006)ATT&CK techniques: Account Discovery (T1087) Brute Force (T1110)Required data: XDR AgentAttacker's goals: Discover valid accounts to gain credentials.Investigative actions: Check if the login attempts were part of a legitimate misunderstanding of the system or part of an attack.Variations
Suspicious Remote domain account enumeration
Medium overridden
Multiple non-existing accounts failed to remotely log in to a host in a short period of time. This may indicate an attacker is trying to remotely enumerate accounts. overridden
Remote account enumeration on domain accounts
Low overridden
Multiple non-existing accounts failed to remotely log in to a host in a short period of time. This may indicate an attacker is trying to remotely enumerate accounts. overridden
Remote code execution into Kubernetes Pod Informational 2 variations
A container administration service was used to execute commands within a Kubernetes Pod.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 5 Days
ATT&CK tactics: Execution (TA0002)ATT&CK techniques: Container Administration Command (T1609)Required data: XDR AgentDetector tags: Kubernetes - AGENTAttacker's goals: Attackers may use the container administration commands to execute commands within a Kubernetes Pod.Investigative actions: Check whether the executing process is benign and if this was a desired behavior as part of its normal execution flow.Variations
Remote code execution into Kubernetes Pod from another Pod for the first time
Medium overridden
A container administration service was used to execute commands within a Kubernetes Pod. overridden
Remote code execution into Kubernetes Pod from another Pod
Low overridden
A container administration service was used to execute commands within a Kubernetes Pod. overridden
Remote command execution via wmic.exe Low 1 variation
Remote command execution using the Windows Management Instrumentation command-line tool.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Execution (TA0002)ATT&CK techniques: Windows Management Instrumentation (T1047)Required data: XDR AgentAttacker's goals: The attacker is expanding his reach into your network by executing commands on a remote endpoint.Investigative actions: Examine Alert Details > Overview to identify the source endpoint, process running the command execution, process owner, and execution destination.Variations
Remote command execution via wmic.exe
Medium overridden
Remote command execution using the Windows Management Instrumentation command-line tool. overridden
Remote service command execution from an uncommon source High
A remotely triggered service initiated a command execution by a host that rarely triggers services to other remote hosts.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Lateral Movement (TA0008) Execution (TA0002)ATT&CK techniques: Remote Services (T1021) System Services: Service Execution (T1569.002)Required data: XDR AgentDetector tags: Impacket AnalyticsAttacker's goals: Perform lateral movement to new hosts to expand the foothold within a network.Investigative actions: Investigate the processes being spawned on the host for malicious activities. Correlate the RPC call from the source host and understand which software initiated it.Remote service start from an uncommon source Low
A remotely triggered service initiated by a host that rarely triggers services to other remote hosts.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Lateral Movement (TA0008) Execution (TA0002)ATT&CK techniques: Remote Services (T1021) System Services: Service Execution (T1569.002)Required data: XDR AgentDetector tags: Impacket AnalyticsAttacker's goals: Perform lateral movement to new hosts to expand the foothold within a network.Investigative actions: Investigate the service being spawned on the host for malicious activities. Correlate the RPC call from the source host and understand which software initiated it.Remote usage of AWS Lambda's role Informational Cloud 5 variations
An AWS Lambda's role was used externally of the cloud environment.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 7 Days
ATT&CK tactics: Credential Access (TA0006) Initial Access (TA0001)ATT&CK techniques: Steal Application Access Token (T1528) Unsecured Credentials (T1552) Valid Accounts: Cloud Accounts (T1078.004)Required data: AWS Audit LogAttacker's goals: Exfiltrate token and abuse it remotely.Investigative actions: Check if the IAM role was assumed by an unknown identity. Check what API calls were executed using the access-key.Variations
Remote command line usage of AWS Lambda's role
High overridden
An AWS Lambda's role was used externally of the cloud environment. overridden
Suspicious usage of AWS Lambda's role
Medium overridden
An AWS Lambda's role was used externally of the cloud environment. overridden
Suspicious usage of AWS Lambda's role
Low overridden
An AWS Lambda's role was used externally of the cloud environment. overridden
Suspicious usage of AWS Lambda's role
High overridden
An AWS Lambda's role was used externally of the cloud environment. overridden
Usage of AWS Lambda's role from a known ASN
Informational overridden
An AWS Lambda's role was used externally of the cloud environment. overridden
Remote usage of VM Service Account token Informational Cloud 1 variation
A GCP Service Account token, which is attached to a VM, was used externally of the cloud environment.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 5 Days
ATT&CK tactics: Credential Access (TA0006)ATT&CK techniques: Steal Application Access Token (T1528) Unsecured Credentials (T1552)Required data: Gcp Audit LogAttacker's goals: Exfiltrate token and abuse it remotely.Investigative actions: Check if the service account was attached to a specific VM. Check if the service account was used by a user. Check if the relevant VM is compromised.Variations
Suspicious usage of VM Service Account token
High overridden
A GCP Service Account token, which is attached to a VM, was used externally of the cloud environment. overridden
Remote usage of an AWS service token Low Cloud 1 variation
An AWS service token was used externally of the cloud environment.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 5 Days
ATT&CK tactics: Credential Access (TA0006) Lateral Movement (TA0008) Initial Access (TA0001)ATT&CK techniques: Steal Application Access Token (T1528) Use Alternate Authentication Material: Application Access Token (T1550.001) Unsecured Credentials (T1552) Valid Accounts: Cloud Accounts (T1078.004)Required data: AWS Audit LogAttacker's goals: Exfiltrate a token and abuse it remotely.Investigative actions: Check what actions were executed using the access-key. Check if the IAM role was assumed by a different identity.Variations
Suspicious usage of AWS service token
Medium overridden
An AWS service token was used externally of the cloud environment. overridden
Remote usage of an App engine Service Account token Informational Cloud 1 variation
A GCP Service Account token, which is attached to an app engine, was used externally of the cloud environment.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 5 Days
ATT&CK tactics: Credential Access (TA0006)ATT&CK techniques: Steal Application Access Token (T1528) Unsecured Credentials (T1552)Required data: Gcp Audit LogAttacker's goals: Exfiltrate token and abuse it remotely.Investigative actions: Check if the Service Account was attached to a specific app engine. Check if the Service Account was used by a user. Check if the relevant app engine is compromised.Variations
Suspicious usage of App engine Service Account token
High overridden
A GCP Service Account token, which is attached to an app engine, was used externally of the cloud environment. overridden
Remote usage of an Azure Managed Identity token Low Cloud 4 variations
An Azure Managed Identity token, which is attached to a compute service, was used externally of the cloud environment.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 5 Days
ATT&CK tactics: Credential Access (TA0006)ATT&CK techniques: Steal Application Access Token (T1528) Unsecured Credentials (T1552)Required data: Azure Audit LogDetector tags: Cloud Serverless Function Credentials Theft AnalyticsAttacker's goals: Exfiltrate valid token and abuse it remotely.Investigative actions: Verify whether the Managed Identity should be used remotely. Check what API calls were executed by the Managed Identity. Check if the relevant compute service is compromised.Variations
Remote usage of an Azure Function App's Managed Identity token
Medium overridden
An Azure Managed Identity token, which is attached to a compute service, was used externally of the cloud environment. overridden
Remote usage of an Azure Automation Account's Managed Identity token
Medium overridden
An Azure Managed Identity token, which is attached to a compute service, was used externally of the cloud environment. overridden
Remote usage of an Azure Managed Identity token from an unusual ASN
High overridden
An Azure Managed Identity token, which is attached to a compute service, was used externally of the cloud environment. overridden
Remote usage of an Azure Managed Identity token from an unusual IP
Medium overridden
An Azure Managed Identity token, which is attached to a compute service, was used externally of the cloud environment. overridden
Remote usage of an Azure Service Principal token Informational Cloud 2 variations
An Azure Service Principal token was used externally of the cloud environment.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 5 Days
ATT&CK tactics: Credential Access (TA0006)ATT&CK techniques: Steal Application Access Token (T1528) Unsecured Credentials (T1552)Required data: Azure Audit LogAttacker's goals: Exfiltrate valid token and abuse it remotely.Investigative actions: Verify whether the service principal should be used remotely. Check what API calls were executed by the service principal. Determine whether the service principal is compromised.Variations
Remote usage of an Azure Service Principal token from an unusual ASN
High overridden
An Azure Service Principal token was used externally of the cloud environment. overridden
Remote usage of an Azure Service Principal token from an unusual IP
Medium overridden
An Azure Service Principal token was used externally of the cloud environment. overridden
Removal of an Azure Owner from an Application or Service Principal Informational Cloud 1 variation
An Azure Owner was removed from an application or service principal. This may indicate malicious activity or unauthorized access to the application or service.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Defense Evasion (TA0005)ATT&CK techniques: Indicator Removal (T1070)Required data: Azure Audit LogAttacker's goals: Remove owners from applications for full control of the application or service principal. Manipulate or delete data stored in the Azure environment.Investigative actions: Check the Azure Activity Log to identify which user removed the Azure Owner.* Check the Azure Role Assignments to identify the current Azure Owners.* Check the Application or Service Principal to identify if any changes have been made.Variations
Removal of an Azure AD privileged user from an Application or Service Principal
Low overridden
An Azure Owner was removed from an application or service principal. This may indicate malicious activity or unauthorized access to the application or service. overridden
Retrieval of cloud compute EC2 instance user data Informational Cloud 1 variation
A cloud compute instance user data was retrieved, which may contain startup scripts, configuration parameters, or sensitive information associated with the instance.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Collection (TA0009)ATT&CK techniques: Automated Collection (T1119)Required data: AWS Audit LogAttacker's goals: Access sensitive instance metadata or startup scripts.Investigative actions: Verify whether this action is expected. Inspect the user data script for sensitive data.Variations
Unusual Retrieval of cloud compute instance user data
Low overridden
A cloud compute instance user data was retrieved, which may contain startup scripts, configuration parameters, or sensitive information associated with the instance. overridden
Retrieval of kubelet credentials Informational 1 variation
A process retrieved kubelet credentials.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Credential Access (TA0006)ATT&CK techniques: Unsecured Credentials: Credentials In Files (T1552.001)Required data: XDR AgentDetector tags: Kubernetes - AGENT, Kubernetes Credentials Theft AnalyticsAttacker's goals: Impersonate the node agent to gain control over the cluster.Investigative actions: Look for additional suspicious activities. Verify if the exposed credentials were used to access the API server. Investigate which operations were used against the Kubernetes cluster with the exposed credentials.Variations
Retrieval of kubelet credentials by an unusual process
Low overridden
A process retrieved kubelet credentials. overridden
Run downloaded script using pipe Informational 1 variation
Downloading a script using wget or curl and executing it using a pipe to a shell.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Execution (TA0002)ATT&CK techniques: Command and Scripting Interpreter: Unix Shell (T1059.004)Required data: XDR AgentDetector tags: Kubernetes - AGENT, ContainersAttacker's goals: Attackers may try to download a script using wget or curl.Investigative actions: Check whether the executing process is benign and if this was a desired behavior as part of its normal execution flow.Variations
Run downloaded script using pipe in a Kubernetes pod
Informational overridden
Downloading a script using wget or curl and executing it using a pipe to a shell. overridden
Rundll32.exe executes a rare unsigned module Low 2 variations
Rundll32.exe executes a rare unsigned module, which can indicate an attacker's malicious execution.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Defense Evasion (TA0005)ATT&CK techniques: System Binary Proxy Execution: Rundll32 (T1218.011)Required data: XDR AgentDetector tags: LOLBIN Execution AnalyticsAttacker's goals: Evading detections by running code from a signed Microsoft executable.Investigative actions: Check whether the loaded module with the corresponding hash is benign and if this was a desired behavior as part of its normal execution flow.Variations
Rundll32.exe executes a rare unsigned module with very high entropy
Medium overridden
Rundll32.exe executes a rare unsigned module, which can indicate an attacker's malicious execution. The module executed by Rundll32 has very high entropy. overridden
Rundll32.exe executes a rare unsigned module with suspicious characteristics
Medium overridden
Rundll32.exe executes a rare unsigned module, which can indicate an attacker's malicious execution. overridden
Rundll32.exe running with no command-line arguments Medium
Rundll32.exe is meant to run with parameters, so the absence of them is extremely suspicious; this behavior is used in the default configuration of Cobalt Strike.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Defense Evasion (TA0005)ATT&CK techniques: System Binary Proxy Execution: Rundll32 (T1218.011)Required data: XDR AgentDetector tags: LOLBIN Execution AnalyticsAttacker's goals: Run as a signed Microsoft executables to avoid detection. Rundll32 is the default process used by Cobalt Strike for running post-exploitation tools.Investigative actions: Check for any injection event to the Rundll32 process. Check the causality of execution for any injections.Rundll32.exe spawns conhost.exe Medium
This unusual parent-child process relationship may indicate that an attacker has abused rundll32.exe to run a console-based application such as PowerShell.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Defense Evasion (TA0005)ATT&CK techniques: System Binary Proxy Execution: Rundll32 (T1218.011)Required data: XDR AgentDetector tags: LOLBIN Execution AnalyticsAttacker's goals: Evading detections by running code from a signed Microsoft executable.Investigative actions: Check whether the executing process is benign and if this was a desired behavior as part of its normal execution flow.S3 configuration deletion Informational Cloud
An S3 bucket configuration has been deleted. This may affect the S3 access, and the objects it contains.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Impact (TA0040)ATT&CK techniques: Data Encrypted for Impact (T1486)Required data: AWS Audit LogDetector tags: Cloud Data Asset Disaster Recovery Risks, Cloud Data Asset Stealth Tactics, Cloud Data Asset Configuration, Data Detection & ResponseAttacker's goals: Modify the S3 configuration and expose stored sensitive data.Investigative actions: Check what data is stored on the S3. Check which configuration change has been made. Verify this change did not make this S3 publicly available.SAAS - Email was reported by the user or administrator as a phishing attempt Informational Email 2 variations
An email reported by the user or administrator as a phishing attempt has been detected.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Hour
ATT&CK tactics: Collection (TA0009)ATT&CK techniques: Email Collection (T1114)Required data: Office 365 AuditAttacker's goals: Trick the user into interacting with a malicious email by disguising it as legitimate, potentially leading to credential theft, malware infection, or data exfiltration.Investigative actions: Analyze the sender's IP address and domain reputation. Check if the sender has appeared in other logs or alerts across the organization. Review any URLs or attachments for signs of phishing, malware, or command-and-control communication. Correlate user actions (e.g., link clicks, file downloads) to assess potential compromise. Determine whether similar emails were sent to other users to identify a broader campaign.Variations
SAAS - Phishing report with suspicious verdict on internal domain sender
Low overridden
An email with an internal sender domain was reported as a phishing attempt.This may indicate either a compromised internal account or an external attacker impersonating an internal user. overridden
SAAS - Phishing report with with suspicious verdict
Low overridden
An email with a Malware/Block verdict reported by the user or administrator has been detected. overridden
SCCM log files enumeration Informational Identity Analytics 1 variation
Multiple local SCCM logs were accessed within a short period of time.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- 1 Hour
- Deduplication:
- 1 Day
ATT&CK tactics: Discovery (TA0007)ATT&CK techniques: Log Enumeration (T1654)Required data: XDR Agent with eXtended Threat Hunting (XTH)Detector tags: Microsoft SCCM AnalyticsAttacker's goals: Enumerate data about the SCCM configuration, infrastructure and deployments.Investigative actions: Check suspicious network connections from the process or host. Check if the user account that initiated the enumeration is supposed to access these files.Variations
Suspicious SCCM log files enumeration
Low overridden
Multiple local SCCM logs were abnormally accessed within a short period of time. overridden
SES Production Access Requested Informational Cloud 1 variation
An identity requested to move the SES account from a restricted sandbox mode into production mode.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Resource Development (TA0042)ATT&CK techniques: Compromise Accounts: Email Accounts (T1586.002)Required data: AWS Audit LogAttacker's goals: Use the existing account to send phishing or spread malware at scale.Investigative actions: Check if the identity has performed any email-related operations in the past. Check if this account should be used for email sending.Variations
SES Production Access Requested by an unusual identity
Low overridden
An identity requested to move the SES account from a restricted sandbox mode into production mode. The identity was not seen performing any operations in SES in the last 30 days. overridden
SMB Traffic from Non-Standard Process Low 1 variation
SMB traffic is usually performed by a standard set of privileged processes through designated ports. The endpoint had a non-standard process communicating over ports normally used by SMB. An attacker might be moving laterally by using tools that implement a custom version of the SMB protocol.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Hour
ATT&CK tactics: Discovery (TA0007)ATT&CK techniques: Network Service Discovery (T1046)Required data: XDR AgentAttacker's goals: This might be symptomatic of an attacker's lateral movements. The attacker could be:* using a custom protocol implementation that offers malicious functionality Using the well-known SMB port with a different protocol to evade detection. Either way, the attacker's goal is to gain access to another endpoint on your network. The attacker could also be surveying your network by performing service scans over the well-known SMB or Kerberos ports.Investigative actions: Make sure the process is not a scanner that implements its version of the protocol, and that the scanner use is for sanctioned purposes. For example, nmap enumerating SMB. Make sure the process is not a sanctioned security product that creates standalone binaries for its use. For example, Illusive Network honeypots. Investigate the process to see if the high-level language used to implement the application is the source of the alert. Some high-level programming languages provide their protocol implementations. For example, Java uses its Kerberos implementation. Examine the endpoint to see if it is infected with malware. If the parent-child chain of initiating processes has been infiltrated with a malicious replacement, then that replacement could be known malware.Variations
SMB Traffic from Non-Standard Process on a sensitive server
Medium overridden
SMB traffic is usually performed by a standard set of privileged processes through designated ports. The endpoint had a non-standard process communicating over ports normally used by SMB. An attacker might be moving laterally by using tools that implement a custom version of the SMB protocol. overridden
SPNs cleared from a machine account Low Identity Analytics 1 variation
Service principal names were cleared from a machine account.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Privilege Escalation (TA0004) Persistence (TA0003)ATT&CK techniques: Account Manipulation (T1098) Valid Accounts (T1078)Required data: Windows Event Collector XDR Agent with eXtended Threat Hunting (XTH)Attacker's goals: Elevate privileges from standard domain user to domain admin.Investigative actions: Follow actions performed by the user. Look for associated sAMAccountName rename events.Variations
SPNs cleared from a machine account for the first time
Medium overridden
Service principal names were cleared from a machine account. overridden
SSH authentication brute force attempts Informational Identity Analytics 2 variations
A user attempted to authenticate via SSH an excessive number of times in a short period. This may indicate a brute force attack.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- 15 Minutes
- Deduplication:
- 3 Hours
ATT&CK tactics: Credential Access (TA0006)ATT&CK techniques: Brute Force (T1110)Required data: XDR AgentAttacker's goals: Attackers attempt to log in to a remote host.Investigative actions: Verify any successful authentication by the user account referenced by the alert, as these can indicate the attacker managed to guess the credentials.Variations
Successful SSH Brute Force
Low overridden
A user successfully authenticated via SSH after an excessive number of failures in a short period. overridden
Possible SSH Brute Force
Low overridden
A user attempted to authenticate via SSH an excessive number of times in a short period. This may indicate a brute force attack. overridden
SSO Brute Force Informational Identity Analytics 3 variations
An abnormally high amount of SSO authentication attempts were seen within a short period of time. This may have resulted from a brute-force attack.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- 1 Hour
- Deduplication:
- 1 Day
ATT&CK tactics: Credential Access (TA0006) Resource Development (TA0042)ATT&CK techniques: Brute Force (T1110) Brute Force: Password Guessing (T1110.001) Compromise Accounts (T1586)Required data: AzureAD Azure SignIn Log Idira Duo Okta OneLogin PingOneAttacker's goals: An attacker is attempting to gain access to an account secured with MFA.Investigative actions: Check the legitimacy of this activity and determine whether it is malicious or not. Check if the user usually logs in from this country. Check whether a successful login was made after unsuccessful attempts.Variations
SSO Brute Force on a Honey User Account
Medium overridden
An abnormally high amount of SSO authentication attempts were seen within a short period of time. This may have resulted from a brute-force attack. overridden
Successful SSO Brute Force Threat Detected
Medium overridden
An abnormally high amount of SSO authentication attempts were seen within a short period of time. This may have resulted from a brute-force attack. overridden
SSO Brute Force Activity Observed
Low overridden
An abnormally high amount of SSO authentication attempts were seen within a short period of time. This may have resulted from a brute-force attack. overridden
SSO Password Spray Informational Identity Analytics 3 variations
An abnormally high amount of SSO authentication attempts were seen within a short period of time. This may have resulted from a login password spray attack.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- 1 Hour
- Deduplication:
- 1 Day
ATT&CK tactics: Credential Access (TA0006) Resource Development (TA0042)ATT&CK techniques: Brute Force: Password Spraying (T1110.003) Brute Force: Password Guessing (T1110.001) Compromise Accounts (T1586)Required data: AzureAD Azure SignIn Log Idira Duo Okta OneLogin PingOneAttacker's goals: An attacker may be attempting to gain unauthorized access to user accounts.Investigative actions: See whether this was a legitimate action. Check if the user usually logs in from this country. Check whether a successful login was made after unsuccessful attempts.Variations
SSO Password Spray Involving a Honey User
Medium overridden
An abnormally high amount of SSO authentication attempts were seen within a short period of time. This may have resulted from a login password spray attack. overridden
SSO Password Spray Threat Detected
Medium overridden
An abnormally high amount of SSO authentication attempts were seen within a short period of time. This may have resulted from a login password spray attack. overridden
SSO Password Spray Activity Observed
Low overridden
An abnormally high amount of SSO authentication attempts were seen within a short period of time. This may have resulted from a login password spray attack. overridden
SSO authentication attempt by a honey user Low Identity Analytics 1 variation
An SSO authentication attempt was made by a honey user, a decoy account created specifically to detect unauthorized access. This may indicate potential attacker activity.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Hour
ATT&CK tactics: Initial Access (TA0001)ATT&CK techniques: Valid Accounts (T1078)Required data: AzureAD Okta OneLogin PingOneDetector tags: Honey User AnalyticsAttacker's goals: An attacker is attempting to gain unauthorized access by exploiting valid or stolen credentials.Investigative actions: Confirm that the alert was triggered by a honey user account. Check for other login attempts on different accounts from the same source IP. Analyze any subsequent actions performed by the user after the login attempt. Follow further actions performed by the user.Variations
Abnormal SSO authentication by a honey user
Medium overridden
An SSO authentication attempt was made by a honey user, a decoy account created specifically to detect unauthorized access. This may indicate potential attacker activity. overridden
SSO authentication by a machine account Low Identity Analytics 1 variation
A machine account successfully authenticated via SSO.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Initial Access (TA0001)ATT&CK techniques: Valid Accounts: Domain Accounts (T1078.002)Required data: AzureAD Azure SignIn Log Idira Duo Okta OneLogin PingOneAttacker's goals: Use an account that has access to resources to move laterally in the network and access privileged resources.Investigative actions: Check whether the account has done any administrative actions it should not usually do. Look for more logins and authentications by the account throughout the network.Variations
SSO authentication by a machine account from a suspicious IP
Medium overridden
A machine account successfully authenticated via SSO. overridden
SSO authentication by a service account Low Identity Analytics 3 variations
A service account successfully authenticated via SSO.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 2 Days
ATT&CK tactics: Initial Access (TA0001)ATT&CK techniques: Valid Accounts: Domain Accounts (T1078.002)Required data: AzureAD Azure SignIn Log Idira Duo Okta OneLogin PingOneAttacker's goals: Use an account that has access to resources to move laterally in the network and access privileged resources.Investigative actions: Check whether the account has done any administrative actions it should not usually do. Look for more logins and authentications by the account throughout the network.Variations
Rare non-interactive SSO authentication by a service account
Informational overridden
A service account successfully authenticated via SSO. overridden
SSO authentication by a service account via a suspicious IP
Low overridden
A service account successfully authenticated via SSO. overridden
First time SSO authentication by a service account
Medium overridden
A service account successfully authenticated via SSO for the first time over the past 30 days. overridden
SSO with abnormal operating system Informational Identity Analytics
A user successfully authenticated via SSO with an abnormal operating system.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Initial Access (TA0001)ATT&CK techniques: Valid Accounts: Domain Accounts (T1078.002)Required data: AzureAD Okta OneLoginAttacker's goals: Use a legitimate user and authenticate via an SSO service to gain access to the network.Investigative actions: Confirm that the activity is benign (e.g. the user has really moved to a new operating system). Follow actions and suspicious activities regarding the user.SSO with abnormal user agent Informational Identity Analytics 1 variation
A user successfully authenticated via SSO with an abnormal user agent.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Initial Access (TA0001)ATT&CK techniques: Valid Accounts: Domain Accounts (T1078.002)Required data: Okta AzureAD Azure SignIn Log Duo PingOneAttacker's goals: Use a legitimate user and authenticate via an SSO service to gain access to the network.Investigative actions: Confirm that the activity is benign (e.g. the user has really moved to a new user agent app). Follow actions and suspicious activities regarding the user.Variations
SSO with an offensive user agent
Low overridden
A user successfully authenticated via SSO with an offensive user agent. overridden
SSO with new operating system Informational Identity Analytics
A user successfully authenticated via SSO with a new operating system.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Initial Access (TA0001)ATT&CK techniques: Valid Accounts: Domain Accounts (T1078.002)Required data: Okta Azure SignIn Log AzureAD DuoAttacker's goals: Use a legitimate user and authenticate via an SSO service to gain access to the network.Investigative actions: Confirm that the activity is benign (e.g. the user has really moved to a new operating system). Follow actions and suspicious activities regarding the user.SUID/GUID permission discovery Low
Attackers may search for potential to elevate permissions using binaries that have the SUID or GUID bit enabled.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Discovery (TA0007)ATT&CK techniques: File and Directory Discovery (T1083)Required data: XDR AgentAttacker's goals: Attackers may use GUID/SUID binaries to elevate privileges.Investigative actions: Check whether additional malicious commands were executed from the same process. Verify if the command-line seems suspicious or contains malicious indicators.SaaS suspicious external domain user activity Informational Identity Threat Module, SaaS Threat Detection 1 variation
An operation was performed by an identity. This identity belongs to a domain that was not seen in the organization before.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Initial Access (TA0001)ATT&CK techniques: External Remote Services (T1133)Required data: Google Workspace Audit Logs Office 365 AuditAttacker's goals: Gain their initial foothold within the organization and explore the environment to achieve their target.Investigative actions: Investigate the external domain name. Check the identity activity in the organization.Variations
Suspicious external user activity detected from a domain first seen in the organization
Low overridden
An operation was performed by an identity. This identity belongs to a domain that was not seen in the organization, both in cloud and SaaS environments. overridden
Scheduled Task hidden by registry modification Low
Attackers may try to hide a Scheduled Task by deleting the Scheduled Task's software descriptor (SD) value in the registry.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Defense Evasion (TA0005)ATT&CK techniques: Modify Registry (T1112) Hide Artifacts (T1564)Required data: XDR Agent with eXtended Threat Hunting (XTH)Attacker's goals: Adversaries may hide their malicious Scheduled Task to evade detection.Investigative actions: Check the appropriate Scheduled Task to verify its legitimacy. You can also check the executing executable to verify its purpose.Scrcons.exe Rare Child Process Informational 1 variation
The Windows Management Instrumentation (WMI) standard event consumer scrcons.exe executed a rare VBScript or PowerShell script. Executing a rare script can be an indication of local or remote code execution abuse by an attacker.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Execution (TA0002) Persistence (TA0003)ATT&CK techniques: Windows Management Instrumentation (T1047) Event Triggered Execution: Windows Management Instrumentation Event Subscription (T1546.003)Required data: XDR AgentAttacker's goals: The attacker is trying to gain Persistence via WMI script registration.Investigative actions: Search for any executions of the Managed Object Format (MOF) compiler mofcomp.exe and review the process that ran it. Review registered WMI ActiveScriptEventConsumer by running "WMIC /namespace:\root\default path ActiveScriptEventConsumer get *".Variations
Scrcons.exe Rare Child Process
Medium overridden
The Windows Management Instrumentation (WMI) standard event consumer scrcons.exe executed a rare VBScript or PowerShell script. Executing a rare script can be an indication of local or remote code execution abuse by an attacker. overridden
Screensaver process executed from Users or temporary folder Low 1 variation
An executable file with a screensaver extension was executed from the Users or temp folder. This is not a common behavior for screensavers and may indicate a malicious file disguised as a screensaver in the Users or temp folder. It is recommended to further investigate the execution flow for malicious indicators.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 6 Hours
ATT&CK tactics: Persistence (TA0003)ATT&CK techniques: Event Triggered Execution: Screensaver (T1546.002)Required data: XDR AgentAttacker's goals: Gain persistence by configuring a new screensaver.Investigative actions: Check whether the executing process (with the SCR extension) is benign and if this was a desired behavior as part of its normal execution flow.Variations
Screensaver process executed from Users or temporary folder by a scripting engine process
High overridden
An executable file with a screensaver extension was executed from the Users or temp folder by a scripting engine process. This is not a common behavior for screensavers and may indicate a malicious file disguised as a screensaver in the Users or temp folder. It is recommended to further investigate the execution flow for malicious indicators. overridden
Script file added to startup-related Registry keys Medium
An attacker may add a script file to the Registry "Run Keys" or the "Winlogon\Userinit" key to cause it to be executed as the user logs in.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Persistence (TA0003)ATT&CK techniques: Boot or Logon Autostart Execution (T1547)Required data: XDR AgentAttacker's goals: Gain persistence using the legitimate Windows registry run key mechanism, which executes commands on user login or computer boot.Investigative actions: Verify if the registered script is malicious. Check if the installed software is a malicious binary or script.Scripting engine connected to a rare external host Low 3 variations
Scripts connecting to external IP addresses may be sanctioned IT scripts. However, when those external IP addresses are only receiving connections from a few specific endpoints in the organization, these scripts may be an indicator of more suspicious activity. Security testers and adversaries use offensive frameworks that employ forms of scripting which result in this type of network activity.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Command and Control (TA0011) Execution (TA0002)ATT&CK techniques: Application Layer Protocol (T1071) Command and Scripting Interpreter (T1059)Required data: XDR AgentDetector tags: EDR Windows C2 AnalyticsAttacker's goals: Connect to the attacker's Command and Control server.Investigative actions: Check the external address the process connects to. Fetch and investigate the executed script.Variations
Scripting engine failed to connect to a rare external host
Informational overridden
Scripts connecting to external IP addresses may be sanctioned IT scripts. However, when those external IP addresses are only receiving connections from a few specific endpoints in the organization, these scripts may be an indicator of more suspicious activity. Security testers and adversaries use offensive frameworks that employ forms of scripting which result in this type of network activity. overridden
Scripting engine with a modified image name connected to a rare external host
Low overridden
Scripts connecting to external IP addresses may be sanctioned IT scripts. However, when those external IP addresses are only receiving connections from a few specific endpoints in the organization, these scripts may be an indicator of more suspicious activity. Security testers and adversaries use offensive frameworks that employ forms of scripting which result in this type of network activity. overridden
Windows LOLBIN scripting engine connected to a rare external host
Medium overridden
Scripts connecting to external IP addresses may be sanctioned IT scripts. However, when those external IP addresses are only receiving connections from a few specific endpoints in the organization, these scripts may be an indicator of more suspicious activity. Security testers and adversaries use offensive frameworks that employ forms of scripting which result in this type of network activity. overridden
SecureBoot was disabled Low
SecureBoot was disabled, this might be indicative of someone trying to install an alternate non-UEFI supported OS.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 14 Days
ATT&CK tactics: Persistence (TA0003)ATT&CK techniques: Pre-OS Boot (T1542)Required data: XDR Agent with eXtended Threat Hunting (XTH)Attacker's goals: Disable SecureBoot to install another OS on the machine.Investigative actions: Check if a new operating system was installed on the same hardware.Security object deletion in Google Workspace Admin Console Informational Identity Threat Module, SaaS Threat Detection 1 variation
A security object was deleted in Google Workspace Admin Console.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Defense Evasion (TA0005)ATT&CK techniques: Impair Defenses: Disable or Modify Tools (T1562.001)Required data: Google Workspace Audit LogsDetector tags: Google WorkspaceAttacker's goals: Adversaries may modify or disable security rules to avoid detection of their activities.Investigative actions: Investigate the security object name deleted and whether it was intended. Check if the user was recently granted new elevated permissions that allowed them to delete security rules. Follow other administrative or suspicious actions performed by this user around the same time.Variations
Security object deletion in Google Workspace Admin Console for the first time
Low overridden
A security object was deleted in Google Workspace Admin Console. overridden
Security tools detection attempt Informational
A script has executed commands that can be used to detect security tools.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Defense Evasion (TA0005) Discovery (TA0007)ATT&CK techniques: Virtualization/Sandbox Evasion (T1497) Virtualization/Sandbox Evasion: System Checks (T1497.001)Required data: XDR Agent with eXtended Threat Hunting (XTH)Attacker's goals: Avoid detection by identifying execution alongside security tools that may alert on a malicious script.Investigative actions: Review the script for additional malicious actions. Check for any additional alerts raised within the same context of the script.Sending unusual file(s) to an external address Low Email
Unusual files sent to an external address.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Hour 30 Minutes
ATT&CK tactics: Initial Access (TA0001) Exfiltration (TA0010)ATT&CK techniques: Phishing (T1566) Exfiltration Over Alternative Protocol (T1048)Required data: Microsoft 365 EmailsDetector tags: ExfiltrationAttacker's goals: Extracting sensitive credentials, potentially leading to account takeover or unauthorized access to internal services. Extracting valuable information outside the company.Investigative actions: Check the content of the unusual files that were sent. Review the external recipient address and assess its reputation. Review past emails sent from this mailbox for any suspicious activity. Check for unusual emails sent to this recipient's address. Monitor further actions taken, such as accessing private keys, API tokens and sensitive data.Sensitive Exchange mail sent to external users Informational Identity Threat Module, SaaS Threat Detection, Email 2 variations
A user sent sensitive email messages to external users.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- 1 Hour
- Deduplication:
- 1 Day
ATT&CK tactics: Collection (TA0009) Exfiltration (TA0010)ATT&CK techniques: Email Collection (T1114) Exfiltration Over Alternative Protocol (T1048)Required data: Office 365 AuditDetector tags: O365 DLP AnalyticsAttacker's goals: An attacker is attempting to collect sensitive email information.Investigative actions: Look for signs that the user account and mailboxes are compromised (e.g. abnormal logins, unusual activity). Follow further actions done by the account. Look for unusual email patterns from the affected mailbox (e.g. unusual email contents). Examine the user's email activity history for suspicious behavior.Variations
Exchange mail to external account matching high severity DLP rules
Low overridden
A user sent sensitive email messages to external users. overridden
Sensitive Exchange mail sent to an external user
Low overridden
A user sent sensitive email messages to external users. overridden
Sensitive account password reset attempt Informational Identity Analytics 1 variation
An attempt was made to reset a sensitive account's password.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Impact (TA0040)ATT&CK techniques: Account Access Removal (T1531)Required data: Windows Event Collector XDR Agent with eXtended Threat Hunting (XTH)Attacker's goals: An attacker may attempt to gain access to the account.Investigative actions: Verify this action with the user who performed the change.Variations
Sensitive account password reset attempt for the first time
Low overridden
An attempt was made to reset a sensitive account's password. overridden
Sensitive browser credential files accessed by a rare non browser process Informational 1 variation
Sensitive browser credential files accessed by a rare non browser process.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Credential Access (TA0006)ATT&CK techniques: Credentials from Password Stores: Credentials from Web Browsers (T1555.003)Required data: XDR Agent with eXtended Threat Hunting (XTH)Attacker's goals: Achieve Credential Access by harvesting credentials from local browser storage. This facilitates Lateral Movement and Persistence across the environment to gain unauthorized control over sensitive resources and information.Investigative actions: Determine the legitimacy of the actor process that accessed the sensitive browser credential files. Analyze the process signature, file path, and command line arguments to verify the process's authenticity. Identify the process or user responsible for initiating the activity and assess its legitimacy.Variations
Sensitive browser credential files accessed by a rare non browser process from a commonly abused directory
Low overridden
Sensitive browser credential files accessed by a rare non browser process. overridden
Serial console access was enabled in AWS account Informational Cloud
Serial console access to EC2 instances was enabled in an AWS account.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 5 Days
ATT&CK tactics: Lateral Movement (TA0008)ATT&CK techniques: Remote Services: Direct Cloud VM Connections (T1021.008) Remote Services: Cloud Services (T1021.007)Required data: AWS Audit LogAttacker's goals: Utilize direct access to virtual infrastructure to pivot through a cloud environment.Investigative actions: Verify whether serial console access should be enabled.* Investigate which actions were performed via serial console access.Service execution via sc.exe Informational
Sc.exe has the ability to start services on local and remote hosts. An attacker may abuse it to execute malicious services on a host.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Execution (TA0002)ATT&CK techniques: System Services: Service Execution (T1569.002)Required data: XDR AgentDetector tags: Malicious Service AnalyticsAttacker's goals: Execute commands and run code on local or remote hosts.Investigative actions: Check whether the service that was created via sc.exe is benign and if this was a desired behavior as part of its normal execution flow.Service ticket request with a spoofed sAMAccountName Medium Identity Analytics
A Kerberos service ticket (ST) was requested for an account with a spoofed sAMAccountName.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 3 Hours
ATT&CK tactics: Privilege Escalation (TA0004) Persistence (TA0003)ATT&CK techniques: Account Manipulation (T1098) Valid Accounts (T1078)Required data: Windows Event Collector XDR Agent with eXtended Threat Hunting (XTH)Attacker's goals: Elevate privileges from standard domain user to domain admin.Investigative actions: Check if the domain controller is patched or vulnerable to the attack. Look for associated sAMAccountName rename events. Follow actions by the account and if it performed a DCSync.Setting Windows Auto Logon by uncommon process Low
Setting Windows Auto Logon by uncommon process.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Persistence (TA0003)ATT&CK techniques: Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder (T1547.001)Required data: XDR Agent with eXtended Threat Hunting (XTH)Attacker's goals: Adversary may attempt to set auto logon for persistence and privilege escalation.Investigative actions: Investigate the process that set or create the registry key.Setuid and Setgid file bit manipulation Low 1 variation
The setuid or setgid bits were set on a file.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Privilege Escalation (TA0004) Defense Evasion (TA0005)ATT&CK techniques: Abuse Elevation Control Mechanism: Setuid and Setgid (T1548.001)Required data: XDR AgentDetector tags: Kubernetes - AGENT, ContainersAttacker's goals: Attackers may try to run the executable application as a different user.Investigative actions: Verify that this isn't IT activity. Look for other hosts executing similar commands.Variations
Setuid and Setgid file bit manipulation in a Kubernetes pod
Low overridden
The setuid or setgid bits were set on a file. overridden
SharePoint Site Collection admin group addition Informational Identity Threat Module, SaaS Threat Detection 2 variations
A user made an addition to the site collection administrators group in SharePoint.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Persistence (TA0003)ATT&CK techniques: Account Manipulation: Additional Cloud Roles (T1098.003)Required data: Office 365 AuditAttacker's goals: Elevate permissions and establish persistence.Investigative actions: Check the IP address from which the access originated. Verify the activity with the performing user. Follow further actions done by the account.Variations
SharePoint site collection admin added to personal site
Informational overridden
A user was added as a site collection admin to a personal site, indicating that the user has accessed the SharePoint service for the first time. overridden
Abnormal SharePoint Site Collection admin group addition
Low overridden
A user made an addition to the site collection administrators group in SharePoint. This user has not made any SharePoint site admin additions over the past 30 days. overridden
Short-lived Azure AD user account Informational Identity Threat Module, SaaS Threat Detection 1 variation
An Azure AD user was created and deleted within a short period of time.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- 1 Hour
- Deduplication:
- 1 Day
ATT&CK tactics: Defense Evasion (TA0005)ATT&CK techniques: Valid Accounts (T1078)Required data: AzureAD Audit LogAttacker's goals: Evasion using a valid account.Investigative actions: Check the user who created the account and verify the activity. Confirm that the account creation was not accidental.Variations
Abnormal Short-lived Azure AD user account
Low overridden
An Azure AD user was created and deleted within a short period of time. overridden
Short-lived user account Low Identity Analytics 2 variations
A user was created and deleted within a short period of time.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- 1 Hour
- Deduplication:
- 1 Hour
ATT&CK tactics: Defense Evasion (TA0005)ATT&CK techniques: Valid Accounts (T1078)Required data: Windows Event Collector XDR Agent with eXtended Threat Hunting (XTH)Attacker's goals: Evasion using a valid account.Investigative actions: Check the user who created the account and verify the activity. Confirm that the account creation was not accidental.Variations
Abnormal short-lived user account
Low overridden
A user was observed creating and deleting an account a short time later. This user does not regularly create and delete accounts. overridden
Short-lived hidden user account
Medium overridden
A user was created with a name that mimics a machine account and later deleted within a short period of time. This may be an attacker's attempt to evade detection. overridden
Signed process creates a scheduled task via file access Informational 1 variation
A signed process created a scheduled task via file access. Attackers may create scheduled tasks for execution and to establish persistence.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Execution (TA0002) Persistence (TA0003)ATT&CK techniques: Scheduled Task/Job (T1053)Required data: XDR AgentDetector tags: Scheduled tasks AnalyticsAttacker's goals: An attacker may gain persistence and execute malicious tools via scheduled tasks.Investigative actions: Check the created task file and look for the action triggered by the task.Variations
Signed process running from an untrusted directory creates a scheduled task via file access
Low overridden
A signed process created a scheduled task via file access. Attackers may create scheduled tasks for execution and to establish persistence. overridden
Signed process performed an unpopular DLL injection Informational 4 variations
A signed process performed an unpopular DLL injection into another process.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Defense Evasion (TA0005)ATT&CK techniques: Process Injection (T1055)Required data: XDR AgentDetector tags: Injection AnalyticsAttacker's goals: Attackers may inject code into processes to evade process-based defenses, as well as possibly elevate privileges.Investigative actions: Check whether the injecting process is benign and if this was a desired behavior as part of its normal execution flow.Variations
Signed process that got injected performed an unpopular and suspicious dll injection
High overridden
A signed process performed an unpopular DLL injection into another process. overridden
Signed process that got injected performed an unpopular and suspicious dll injection
Medium overridden
A signed process performed an unpopular DLL injection into another process. overridden
Signed process that got injected performed an unpopular dll injection
Medium overridden
A signed process performed an unpopular DLL injection into another process. overridden
Signed process performed an unpopular DLL injection
Low overridden
A signed process performed an unpopular DLL injection into another process. overridden
Signed process performed an unpopular injection Informational 6 variations
A signed process performed an unpopular injection to another process.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Defense Evasion (TA0005)ATT&CK techniques: Process Injection (T1055)Required data: XDR AgentDetector tags: Injection AnalyticsAttacker's goals: Attackers may inject code into processes to evade process-based defenses, as well as possibly elevate privileges.Investigative actions: Check whether the injecting process is benign and if this was a desired behavior as part of its normal execution flow.Variations
Signed process that got injected performed an unpopular and suspicious injection
Medium overridden
A signed process performed an unpopular injection to another process. overridden
Signed process that got injected performed an unpopular and suspicious injection
Medium overridden
A signed process performed an unpopular injection to another process. overridden
Signed process that got injected performed an unpopular injection
Medium overridden
A signed process performed an unpopular injection to another process. overridden
Commonly abused signed process performed a globally unpopular injection to a Microsoft signed process
Medium overridden
A signed process performed an unpopular injection to another process. overridden
Signed process performed an unpopular injection
Low overridden
A signed process performed an unpopular injection to another process. overridden
Signed process executed by a scheduled task performed an unpopular injection
Low overridden
A signed process performed an unpopular injection to another process. overridden
Single account excessively locked out Informational Identity Analytics 1 variation
A user has been locked out an unusually high number of times within a short timeframe. This could indicate an attempt to gain unauthorized access to the user's account.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- 1 Hour
- Deduplication:
- 1 Day
ATT&CK tactics: Credential Access (TA0006)ATT&CK techniques: Brute Force (T1110) Brute Force: Password Spraying (T1110.003)Required data: Windows Event Collector XDR Agent with eXtended Threat Hunting (XTH)Attacker's goals: An attacker may be attempting to gain unauthorized access to user accounts.Investigative actions: Investigate the associated authentication attempts and login failures (e.g. 4740, 4625, 4776 events). Check if there were any successful authentications (event ID 4624). Determine if any programs have stored outdated credentials, causing account lockouts. Check recent user activity for unusual behavior, such as logins from unfamiliar locations or devices. Confirm whether the user's credentials have been compromised or leaked. Review if the account is enrolled in multifactor authentication (MFA). Find the computer responsible for the lockouts and verify if it exists on the domain. Monitor services that may be running with a user's credentials.Variations
Single suspicious account excessively locked out
Low overridden
A user has been locked out an unusually high number of times within a short timeframe. This could indicate an attempt to gain unauthorized access to the user's account. overridden
Soft delete of cloud storage configuration was disabled Informational Cloud
A Soft Delete configuration was disabled on a cloud storage account. Soft delete allows a deletion of a blob or a container to be restored. Disabling it will impair the ability of the cloud environment to recover in disaster scenarios.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Impact (TA0040)ATT&CK techniques: Inhibit System Recovery (T1490)Required data: Azure Audit LogDetector tags: Cloud Data Asset Disaster Recovery Risks, Cloud Data Asset Protection Tampering, Cloud Data Asset Configuration, Data Detection & ResponseAttacker's goals: Impair the ability of the cloud environment to recover in disaster scenarios.Investigative actions: Check if the identity intended to disable soft delete for this storage account. Check if the identity performed additional malicious operations in the cloud environment.Space after filename Informational
A file was created or renamed to have a space at the end of its name.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Defense Evasion (TA0005)ATT&CK techniques: Masquerading: Space after Filename (T1036.006)Required data: XDR Agent with eXtended Threat Hunting (XTH)Attacker's goals: Attackers may try to change the extension of the file to evade detection.Investigative actions: Verify that this isn't IT activity. Look for other hosts executing similar commands.Spam Bot Traffic Low 2 variations
The endpoint connected to an excessive number of external SMTP servers. A spambot may be trying to send spam email using multiple SMTP servers. Spambots can cause your domain to be blacklisted, and can contain other malicious functionality. The same mechanism can also be used for exfiltration. Some VPN clients can also tunnel data over SMTP. Note: This detection model looks for SMTP connections to external servers, but the volume of traffic is not considered. A count is performed based on the number of domains being contacted, as well as the number of unresolved IP addresses.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- 3 Days
- Deduplication:
- 3 Days
ATT&CK tactics: Impact (TA0040)ATT&CK techniques: Resource Hijacking (T1496)Required data: Palo Alto Networks Firewall traffic Logs XDR Agent Third-Party FirewallsAttacker's goals: The attacker uses the host as an SMTP client to send mails and hide their real origin.Investigative actions: Verify that the source is not an SMTP server. If Cortex XDR Analytics has failed to identify the process as a valid SMTP server, this alert will be a false positive. Verify that IP addresses are actually not being resolved by the non-SMTP process. If the process is performing DNS resolution with a DNS service outside your network, it is possible (depending on your network topology) that Cortex XDR Analytics will not observe that traffic. Because SMTP services typically use numerous IP addresses, this situation could cause a process to exceed a limit when it would otherwise fail to do so. If the SMTP connection activity turns out to be the result of malicious file activity, search on the Triage page for other endpoints infected with the file.Variations
Spam Bot Traffic
Informational overridden
The endpoint connected to an excessive number of external SMTP servers. A spambot may be trying to send spam email using multiple SMTP servers. Spambots can cause your domain to be blacklisted, and can contain other malicious functionality. The same mechanism can also be used for exfiltration. Some VPN clients can also tunnel data over SMTP. Note: This detection model looks for SMTP connections to external servers, but the volume of traffic is not considered. A count is performed based on the number of domains being contacted, as well as the number of unresolved IP addresses. overridden
Failed Spam Bot Traffic
Informational overridden
The endpoint connected to an excessive number of external SMTP servers. A spambot may be trying to send spam email using multiple SMTP servers. Spambots can cause your domain to be blacklisted, and can contain other malicious functionality. The same mechanism can also be used for exfiltration. Some VPN clients can also tunnel data over SMTP. Note: This detection model looks for SMTP connections to external servers, but the volume of traffic is not considered. A count is performed based on the number of domains being contacted, as well as the number of unresolved IP addresses. overridden
Storage enumeration activity Informational Cloud
An identity attempted to discover cloud objects within storage buckets. This might be an attempt by an adversary to find sensitive data stored in cloud storage, which could lead to data theft.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- 10 Minutes
- Deduplication:
- 5 Days
ATT&CK tactics: Discovery (TA0007)ATT&CK techniques: Cloud Storage Object Discovery (T1619) Cloud Infrastructure Discovery (T1580)Required data: AWS Audit Log Azure Audit Log Gcp Audit LogDetector tags: Cloud Data Asset Stealth Tactics, Data Detection & ResponseAttacker's goals: Access sensitive data stored in cloud infrastructure.Investigative actions: Check the identity's role designation in the organization. Identify which storage buckets were enumerated and whether they contained sensitive information.Stored credentials exported using credwiz.exe Low 3 variations
Attackers may abuse the credwiz tool to export stored accounts.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Credential Access (TA0006)ATT&CK techniques: Credentials from Password Stores (T1555)Required data: XDR AgentAttacker's goals: An attacker may attempt to gain higher privileges.Investigative actions: Check whether the executing process is benign and if this was a desired behavior as part of its normal execution flow.Variations
Stored credentials exported using credwiz.exe using keymgr.dll's KRShowKeyMgr function
Medium overridden
Attackers may abuse the credwiz tool to export stored accounts using keymgr.dll's KRShowKeyMgr function. overridden
Stored credentials exported using credwiz.exe over RDP
Low overridden
Attackers may abuse the credwiz tool to export stored accounts over RDP. overridden
Stored credentials exported using credwiz.exe with a built-in Windows tool
Low overridden
Attackers may abuse the credwiz tool to export stored accounts with a built-in Windows tool. overridden
Subdomain Fuzzing Low 1 variation
The root domain within the network is experiencing an unusually high number of access requests to its subdomains, significantly exceeding the typical activity levels for that domain. This anomaly could suggest that someone is attempting to enumerate subdomains or uncover additional virtual hosts associated with the domain, possibly as part of a reconnaissance effort to identify vulnerable or less-secured entry points into the network.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- 20 Minutes
- Deduplication:
- 1 Day
ATT&CK tactics: Reconnaissance (TA0043)ATT&CK techniques: Active Scanning: Wordlist Scanning (T1595.003)Required data: Palo Alto Networks Firewall EAL Logs XDR AgentAttacker's goals: Scan a known external facing asset to gain knowledge about the organization.Investigative actions: Verify that the domain doesn't host numerous subdomains. Verify that the source of the scan is not a known external scanner.Variations
Subdomain Fuzzing To a Rare Destination
Medium overridden
The root domain within the network is experiencing an unusually high number of access requests to its subdomains, significantly exceeding the typical activity levels for that domain. This anomaly could suggest that someone is attempting to enumerate subdomains or uncover additional virtual hosts associated with the domain, possibly as part of a reconnaissance effort to identify vulnerable or less-secured entry points into the network. overridden
Successful universal authentication with suspicious features Informational Identity Analytics 4 variations
A universal authentication was flagged as suspicious based on anomalous features.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Initial Access (TA0001)ATT&CK techniques: Valid Accounts (T1078)Attacker's goals: Use an account that was possibly compromised to gain access to the network, while potentially using an anonymizing service to obfuscate their origin.Investigative actions: Investigate the suspicious authentication. Verify if the ASN is an approved ASN to authenticate from. Follow further actions done by the user. If the IP is associated with a tunnel operator, check whether it is an approved VPN.Variations
Successful universal authentication sign-in from a TOR exit node
Medium overridden
A successful sign-in from a TOR exit node in universal authentication. overridden
Successful universal authentication from a suspicious tunnel operator
Low overridden
A successful universal authentication was made through a suspicious or rarely seen tunnel operator. overridden
Suspicious successful universal authentication from ASN
Informational overridden
A successful universal authentication was made from a suspicious or previously unseen ASN. overridden
Successful universal authentication from a new country in organization
Informational overridden
A user authenticated in universal authentication from an unusual country that no one from this organization has connected from before in universal authentication. This may indicate the account was compromised. overridden
Successful unusual guest user invitation Informational Identity Threat Module, SaaS Threat Detection 1 variation
An identity successfully invited a guest user to the tenant with unusual characteristics.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Persistence (TA0003)ATT&CK techniques: Valid Accounts (T1078)Required data: AzureAD Audit LogAttacker's goals: An attacker can invite users to for evasion.Investigative actions: Check who is the invited guest user. Check whether the inviter is permitted to perform such actions. Check if the domain of the invited guest is allowed for invitations in the organization.Variations
Rare successful guest invitation in the organization
Low overridden
An identity successfully invited a suspicious guest user to the tenant. overridden
Sudden spike in outbound email volume Informational Email 2 variations
Unusual amount of emails sent by an internal sender to one or more external recipients within a short timeframe.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- 1 Hour
- Deduplication:
- 2 Hours
ATT&CK tactics: Execution (TA0002) Credential Access (TA0006)ATT&CK techniques: User Execution (T1204) Brute Force: Password Cracking (T1110.002)Required data: Microsoft 365 EmailsAttacker's goals: Extracting valuable information outside the company. Bypass Data Loss Prevention (DLP) by splitting data across multiple emails.Investigative actions: Check the content of the email that was sent. Review the external recipient address and assess its reputation. Review past emails sent from this mailbox for any suspicious activity. Check for unusual emails sent to this recipient's address. Monitor further action taken, such as accessing to private keys, API tokens and sensitive data.Variations
Sudden spike in outbound emails sent to external recipients
Informational overridden
Unusual amount of emails sent by an internal sender to one or more external recipients within a short timeframe. overridden
Sudden spike in outbound emails sent to internal recipients
Informational overridden
Unusual amount of emails sent by an internal sender to one or more external recipients within a short timeframe. overridden
Sudoedit Brute force attempt Medium
An unusual amount of sudoedit commands executed in a short period of time. This may indicate an attempt to exploit CVE-2021-3156.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- 1 Hour
- Deduplication:
- 1 Day
ATT&CK tactics: Privilege Escalation (TA0004)ATT&CK techniques: Exploitation for Privilege Escalation (T1068)Required data: XDR AgentAttacker's goals: The attacker may gain higher privileges via exploitation of sudoedit.Investigative actions: Verify that the current version of sudo in not vulnerable to CVE-2021-3156.Suspicious .NET process loads an MSBuild DLL Medium
A suspicious process in the Microsoft .NET directory loaded the Microsoft Build Framework DLL. This may occur if an attacker masquerades a process like MSBuild (PowerLessShell).
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Defense Evasion (TA0005)ATT&CK techniques: Trusted Developer Utilities Proxy Execution: MSBuild (T1127.001)Required data: XDR AgentAttacker's goals: Gain code execution on the host and evade security controls.Investigative actions: Check whether the executing process is benign and if this was a desired behavior as part of its normal execution flow.Suspicious AI Dataset Download Low Cloud 1 variation
A model dataset was accessed by an identity that typically doesn't interact with dataset files. MITRE ATLAS Technique: AML.T0035 - ML Artifact Collection.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 5 Days
ATT&CK tactics: Impact (TA0040)ATT&CK techniques: Data Manipulation: Stored Data Manipulation (T1565.001)Required data: AWS Audit Log Azure Audit Log Gcp Audit LogDetector tags: Cloud AI Infrastructure AnalyticsAttacker's goals: Manipulate datasets used by ML models.Investigative actions: Determine which dataset was accessed. Examine the changes made to the dataset.Variations
Suspicious First-Time AI Dataset Download by Identity
Medium overridden
A model dataset was accessed by an identity that typically doesn't interact with dataset files. MITRE ATLAS Technique: AML.T0035 - ML Artifact Collection. overridden
Suspicious AI Dataset Label Modification Low Cloud
AI Dataset labels were modified by an identity that typically doesn't interact with labels. MITRE ATLAS Technique: AML.T0020 - Poison Training Data. OWASP Top 10 LLM Technique: LLM04 - Data and Model Poisoning.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 5 Days
ATT&CK tactics: Impact (TA0040)ATT&CK techniques: Data Manipulation: Stored Data Manipulation (T1565.001)Required data: AWS Audit Log Azure Audit Log Gcp Audit LogDetector tags: Cloud AI Infrastructure AnalyticsAttacker's goals: Contaminating training set, so that predictions on new data will be modified.Investigative actions: Check the identity that modified the dataset's labels. Check that the dataset is correctly labeled.Suspicious AI model usage from a Tor exit node High Cloud 1 variation
A cloud identity invoked an AI model from a Tor exit node.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 5 Days
ATT&CK tactics: Command and Control (TA0011)ATT&CK techniques: Proxy: Multi-hop Proxy (T1090.003)Required data: AWS Audit Log Gcp Audit LogDetector tags: Cloud AI Infrastructure AnalyticsAttacker's goals: Conceal information about malicious activities, such as location and network usage.Investigative actions: Block all web traffic to and from public Tor entry and exit nodes.Variations
Failed AI model usage from a Tor exit node
Informational overridden
A cloud identity invoked an AI model from a Tor exit node. overridden
Suspicious AMSI decode attempt Informational
A script has executed commands that can be used to decode commands or files.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Minute
ATT&CK tactics: Defense Evasion (TA0005)ATT&CK techniques: Deobfuscate/Decode Files or Information (T1140)Required data: XDR Agent with eXtended Threat Hunting (XTH)Attacker's goals: Avoid security mitigations and detections.Investigative actions: Check the payload for malicious activity.Suspicious API call from a Tor exit node High Cloud 2 variations
A cloud API was called from a Tor exit node.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Command and Control (TA0011) Initial Access (TA0001)ATT&CK techniques: Proxy: Multi-hop Proxy (T1090.003) Valid Accounts: Cloud Accounts (T1078.004)Required data: AWS Audit Log Azure Audit Log Gcp Audit Log Kubernetes Audit LogsDetector tags: Kubernetes - API, OCI AnalyticsAttacker's goals: Conceal information about malicious activities, such as location and network usage.Investigative actions: Block all web traffic to and from public Tor entry and exit nodes.Variations
Suspicious Kubernetes API call from a Tor exit node
High overridden
A Kubernetes API was called from a Tor exit node. overridden
A Failed API call from a Tor exit node
Informational overridden
A cloud API was called from a Tor exit node. overridden
Suspicious AWS SSM parameters retrieval activity Informational Cloud 1 variation
An identity dumped multiple AWS SSM parameters from the project. This may indicate an attacker's attempt to dump sensitive information from the cloud environment.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- 1 Hour
- Deduplication:
- 5 Days
ATT&CK tactics: Credential Access (TA0006) Collection (TA0009)ATT&CK techniques: Unsecured Credentials (T1552) Data from Cloud Storage (T1530)Required data: AWS Audit LogDetector tags: SSM Remote Management AnalyticsAttacker's goals: Collect secrets from the cloud environment.Investigative actions: Check the accessed parameters' designation. Verify that the identity did not dump any sensitive information that it shouldn't.Variations
A non admin identity extracted multiple secrets within the organization across multiple regions
Low overridden
An identity dumped multiple AWS SSM parameters from the project. This may indicate an attacker's attempt to dump sensitive information from the cloud environment. overridden
Suspicious Azure AD interactive sign-in using PowerShell Informational Identity Analytics 1 variation
A user interactively logged in to Azure AD via PowerShell.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Initial Access (TA0001)ATT&CK techniques: Valid Accounts (T1078)Required data: AzureADAttacker's goals: The attacker attempts to gain access to the organization's resources.Investigative actions: Analyze the actions taken by the user during the session and verify that this is a legitimate session. Look for signs that the user account is compromised (e.g. abnormal logins, unusual activity).Variations
Unusual Azure AD interactive sign-in using PowerShell
Low overridden
A user interactively logged in to Azure AD via PowerShell from an unusual geolocation or ASN. overridden