Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1300 alerts match the current filters.

Download CSV Show ATT&CK heatmap
  • Tampering with Internet Explorer Protected Mode configuration Informational 2 variations

    When an add-on is running inside Protected Mode attempts to launch a broker process (or any other program), the ElevationPolicy Registry key is checked to determine how the process should be launched. Internet Explorer will run a broker process with higher rights that can use the current user's permissions to take actions that would otherwise be prohibited when rendering content inside the Protected Mode sandbox. https://blogs.msdn.microsoft.com/ieinternals/2009/11/30/understanding-the-protected-mode-elevation-dialog/.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Defense Evasion (TA0005)
    ATT&CK techniques: Impair Defenses: Disable or Modify Tools (T1562.001)
    Required data: XDR Agent
    Attacker's goals: When an add-on is running inside Protected Mode attempts to launch a broker process, this key is checked to determine how the process should be launched. Attackers may change this value to make the process launch with higher privileges.
    Investigative actions: Check whether the injecting process is benign and if this was a desired behavior as part of its normal execution flow.

    Variations

    Tampering with Internet Explorer Protected Mode default configuration

    Medium overridden

    When an add-on is running inside Protected Mode attempts to launch a broker process (or any other program), the ElevationPolicy Registry key is checked to determine how the process should be launched. Internet Explorer will run a broker process with higher rights that can use the current user's permissions to take actions that would otherwise be prohibited when rendering content inside the Protected Mode sandbox. https://blogs.msdn.microsoft.com/ieinternals/2009/11/30/understanding-the-protected-mode-elevation-dialog/. overridden

    Tampering with Internet Explorer Protected Mode specific app configuration

    Informational overridden

    When an add-on is running inside Protected Mode attempts to launch a broker process (or any other program), the ElevationPolicy Registry key is checked to determine how the process should be launched. Internet Explorer will run a broker process with higher rights that can use the current user's permissions to take actions that would otherwise be prohibited when rendering content inside the Protected Mode sandbox. https://blogs.msdn.microsoft.com/ieinternals/2009/11/30/understanding-the-protected-mode-elevation-dialog/. overridden

  • Tampering with the Windows User Account Controls (UAC) configuration Informational 3 variations

    EnableLUA specifies whether Windows User Account Controls (UAC) notifies the user when programs try to modify the computer. UAC was formerly known as Limited User Account (LUA).

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Defense Evasion (TA0005)
    ATT&CK techniques: Abuse Elevation Control Mechanism: Bypass User Account Control (T1548.002)
    Required data: XDR Agent with eXtended Threat Hunting (XTH)
    Attacker's goals: Gain higher privileges by bypassing the User Account Control (UAC).
    Investigative actions: Check whether the executing process is benign and if this was a desired behavior as part of its normal execution flow.

    Variations

    Tampering with the Windows User Account Controls (UAC) configuration by a remote host

    Medium overridden

    EnableLUA specifies whether Windows User Account Controls (UAC) notifies the user when programs try to modify the computer. UAC was formerly known as Limited User Account (LUA). overridden

    Tampering with the Windows User Account Controls (UAC) configuration

    Low overridden

    EnableLUA specifies whether Windows User Account Controls (UAC) notifies the user when programs try to modify the computer. UAC was formerly known as Limited User Account (LUA). overridden

    Tampering with the Windows User Account Controls (UAC) configuration

    Low overridden

    EnableLUA specifies whether Windows User Account Controls (UAC) notifies the user when programs try to modify the computer. UAC was formerly known as Limited User Account (LUA). overridden

  • The CA policy EditFlags was queried Medium

    The CA policy EditFlags was queried.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Privilege Escalation (TA0004)
    ATT&CK techniques: Valid Accounts (T1078)
    Required data: XDR Agent
    Detector tags: Active Directory Certificate Services Analytics
    Attacker's goals: Querying this registry value can indicate an attacker is looking for an enabled EDITF_ATTRIBUTESUBJECTALTNAME2 flag. When this flag is enabled, it allows users to request certificates with a Subject Alternate Name(SAN). This can allow an attacker to obtain a certificate with higher privileges.
    Investigative actions: Check if the action was allowed by the user. Monitor certificate enrollments with Subject Alternate Names. Check for unusual high privilege users certificate authentications.
  • The Linux system firewall was disabled Low

    The system firewall was disabled.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    10 Minutes
    ATT&CK tactics: Defense Evasion (TA0005)
    ATT&CK techniques: Impair Defenses: Disable or Modify System Firewall (T1562.004)
    Required data: XDR Agent
    Attacker's goals: Exfiltrate data or move laterally in the organization.
    Investigative actions: Examine the command to understand which ip or port were affected. Check the communication allowed by the created firewall rule.
  • Training simulation email detected Low Email

    This email was flagged as part of a training simulation.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Hour 30 Minutes
    ATT&CK tactics: Initial Access (TA0001)
    ATT&CK techniques: Phishing (T1566)
    Required data: Microsoft 365 Emails
    Detector tags: Phishing
    Attacker's goals: Impersonate internal users or familiar individuals and trick them into clicking on malicious links or attachments.
    Investigative actions: Check the email address for any unusual spellings. Examine the sender's IP address and reputation. If the message contains attachments or links, scrutinize them for any suspicious indications. Monitor further actions taken, such as file downloads or access to potentially malicious links.
  • Uncommon ARP cache listing via arp.exe Low

    The arp.exe command is used to display and modify entries in the Address Resolution Protocol (ARP) cache. Adversaries may attempt to use the command to discover remote systems they could compromise.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Hour
    ATT&CK tactics: Discovery (TA0007)
    ATT&CK techniques: System Network Configuration Discovery (T1016)
    Required data: XDR Agent
    Attacker's goals: Adversaries may attempt to use the command to discover remote systems they could compromise.
    Investigative actions: Check whether the initiating process is allowed in your organization. (If the parent process is cmd.exe, check the process that spawned it).
  • Uncommon AT task-job creation by user Low 2 variations

    An unpopular AT task-job was created by a user.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Persistence (TA0003)
    ATT&CK techniques: Scheduled Task/Job: At (T1053.002)
    Required data: XDR Agent with eXtended Threat Hunting (XTH)
    Attacker's goals: Attackers may use at task-jobs for persistence or executing malicious files.
    Investigative actions: Check the AT job task for suspicious activity.

    Variations

    Uncommon AT task-job creation by user from a web server process

    Medium overridden

    A web process used the AT command to create a new AT task-job. overridden

    Uncommon AT task-job creation by user from unpopular process

    Low overridden

    An unpopular process created an AT task-job on the host, which is not popular in the organization. overridden

  • Uncommon AppleScript containing a potential obfuscation technique was executed Low 2 variations

    The AppleScript interpreter process was executed with an obfuscation technique in the command line.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Execution (TA0002) Defense Evasion (TA0005)
    ATT&CK techniques: Command and Scripting Interpreter: AppleScript (T1059.002) Obfuscated Files or Information: Command Obfuscation (T1027.010)
    Required data: XDR Agent
    Detector tags: AppleScript Analytics, Evasion Analytics
    Attacker's goals: Evade defenses and impede forensics by encrypting, encoding, or obfuscating payloads at rest or in transit.
    Investigative actions: Analyze the command line and determine whether it performs any malicious or suspicious actions. Check the events generated by the process or its children for potential malicious behavior. Verify the legitimacy of the persistence mechanism being created or modified.

    Variations

    Uncommon AppleScript containing a potential obfuscation technique was executed subsequently running a shell command

    Medium overridden

    The AppleScript interpreter process was executed with an obfuscation technique in the command line. overridden

    Uncommon AppleScript containing a potential obfuscation technique was executed by an uncommon parent process

    High overridden

    The AppleScript interpreter process was executed with an obfuscation technique in the command line. overridden

  • Uncommon AppleScript containing a potential persistence command was executed via the command line Low 2 variations

    The AppleScript interpreter executed an uncommon command potentially used for persistence to maintain system access.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Execution (TA0002) Persistence (TA0003)
    ATT&CK techniques: Command and Scripting Interpreter: AppleScript (T1059.002) Boot or Logon Autostart Execution (T1547)
    Required data: XDR Agent
    Detector tags: AppleScript Analytics, Generic Persistence Analytics
    Attacker's goals: Establish persistence on the system through various mechanisms to maintain access.
    Investigative actions: Analyze the command line and determine whether it performs any malicious or suspicious actions. Check the events generated by the process or its children for potential malicious behavior. Verify the legitimacy of the persistence mechanism being created or modified.

    Variations

    Uncommon AppleScript containing a potential persistence command was executed via the command line targeting a .plist file for modification

    High overridden

    The AppleScript interpreter executed an uncommon command potentially used for persistence to maintain system access. overridden

    Uncommon AppleScript containing a potential persistence command was executed via the command line targeting launchctl load command execution

    Low overridden

    The AppleScript interpreter executed an uncommon command potentially used for persistence to maintain system access. overridden

  • Uncommon AppleScript designed to access credential files was executed via the command line Medium

    The AppleScript interpreter was executed with a script designed to access credential files such as keychains or SSH keys.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Execution (TA0002) Credential Access (TA0006)
    ATT&CK techniques: Command and Scripting Interpreter: AppleScript (T1059.002) Credentials from Password Stores (T1555)
    Required data: XDR Agent
    Detector tags: AppleScript Analytics, Sensitive Information Stealing Analytics
    Attacker's goals: Access stored credentials such as keychains and SSH keys for lateral movement or unauthorized access.
    Investigative actions: Identify which credential files were targeted (keychain, SSH authorized_keys, etc.). Check if credentials or authentication tokens were extracted. Verify the legitimacy of the file access attempt and whether it aligns with the user's normal activity. Examine child processes for signs of data exfiltration.
  • Uncommon AppleScript designed to access cryptocurrency wallet data was executed via the command line Informational 1 variation

    The AppleScript interpreter was executed with a script designed to access cryptocurrency wallet data.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Execution (TA0002) Collection (TA0009)
    ATT&CK techniques: Command and Scripting Interpreter: AppleScript (T1059.002) Data from Local System (T1005)
    Required data: XDR Agent
    Detector tags: AppleScript Analytics, Sensitive Information Stealing Analytics
    Attacker's goals: Exfiltrate cryptocurrency wallet data and seed phrases for direct financial theft.
    Investigative actions: Identify which cryptocurrency wallet application data was targeted. Check if wallet seed phrases, private keys, or transaction data were accessed. Verify whether the process or its children attempted to exfiltrate the wallet data. Determine if the executing user typically uses cryptocurrency applications.

    Variations

    Uncommon AppleScript designed to access cryptocurrency wallet data was executed via the command line accessed crypto wallet's files

    Medium overridden

    The AppleScript interpreter was executed with a script designed to access cryptocurrency wallet data. overridden

  • Uncommon AppleScript designed to access sensitive application data was executed via the command line High

    The AppleScript interpreter was executed with a script designed to access sensitive application data such as Telegram messages, Apple Notes, or cached data.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Execution (TA0002) Collection (TA0009)
    ATT&CK techniques: Command and Scripting Interpreter: AppleScript (T1059.002) Data from Local System (T1005)
    Required data: XDR Agent
    Detector tags: AppleScript Analytics, Sensitive Information Stealing Analytics
    Attacker's goals: Access sensitive application data such as messaging history and notes for intelligence gathering or data exfiltration.
    Investigative actions: Identify which sensitive application data was targeted (Telegram, Apple Notes, cached data, etc.). Check if application databases or message stores were copied or exfiltrated. Verify the legitimacy of the data access attempt and whether it aligns with the user's normal activity. Examine child processes for signs of data exfiltration.
  • Uncommon AppleScript designed to capture screen or clipboard data was executed via the command line Low

    The AppleScript interpreter was executed with a script designed to capture screen content or clipboard data.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Execution (TA0002) Collection (TA0009)
    ATT&CK techniques: Command and Scripting Interpreter: AppleScript (T1059.002) Screen Capture (T1113) Clipboard Data (T1115)
    Required data: XDR Agent
    Detector tags: AppleScript Analytics, Sensitive Information Stealing Analytics
    Attacker's goals: Capture screen content or clipboard data to steal visible credentials, session tokens, or sensitive information.
    Investigative actions: Determine whether the screen capture or clipboard access was initiated by a legitimate application. Check if the captured data was written to a suspicious location or exfiltrated. Verify whether the user was aware of the screen capture activity.
  • Uncommon AppleScript potentially utilizes credential-grabbing techniques to steal user passwords Low 1 variation

    The AppleScript interpreter potentially utilizes credential-grabbing techniques to steal user passwords.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Execution (TA0002) Credential Access (TA0006)
    ATT&CK techniques: Command and Scripting Interpreter: AppleScript (T1059.002) Credentials from Password Stores (T1555)
    Required data: XDR Agent
    Detector tags: AppleScript Analytics, Credentials Grabbing Analytics
    Attacker's goals: Harvest user credentials and passwords from sensitive locations such as the macOS Keychain or directory services to enable unauthorized access, lateral movement, or privilege escalation.
    Investigative actions: Analyze the command line and determine whether it performs any malicious or suspicious actions. Check the events generated by the process or its children for potential malicious behavior. Check whether the process was executed in an unusual way.

    Variations

    Uncommon AppleScript potentially utilizes credential-grabbing techniques to steal user passwords leveraging the 'dscl -authonly' command to covertly verify the captured password

    High overridden

    The AppleScript interpreter potentially utilizes credential-grabbing techniques to steal user passwords. overridden

  • Uncommon AppleScript was executed via the command line to contact an external server Low 2 variations

    The AppleScript interpreter executed a script designed to contact an external server.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Execution (TA0002) Exfiltration (TA0010)
    ATT&CK techniques: Command and Scripting Interpreter: AppleScript (T1059.002) Exfiltration Over C2 Channel (T1041)
    Required data: XDR Agent
    Detector tags: AppleScript Analytics, Abnormal Communication Analytics
    Attacker's goals: Exfiltrate collected data, including sensitive documents and credentials, from the compromised system.
    Investigative actions: Analyze the command line and determine whether it performs any malicious or suspicious actions. Check the events generated by the process or its children for potential malicious behavior. Verify the legitimacy of the persistence mechanism being created or modified.

    Variations

    Uncommon AppleScript was executed via the command line to contact an external server using 'curl' to transfer a .zip file

    Medium overridden

    The AppleScript interpreter executed a script designed to contact an external server. overridden

    Uncommon AppleScript was executed via the command line to contact an external server using 'curl' to upload a file

    Low overridden

    The AppleScript interpreter executed a script designed to contact an external server. overridden

  • Uncommon Azure Cosmos DB master key read by identity Low Cloud

    A cloud identity read master keys from an Azure Cosmos DB account, which is uncommon for this identity.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Credential Access (TA0006)
    ATT&CK techniques: Unsecured Credentials (T1552)
    Required data: Azure Audit Log
    Attacker's goals: Obtain Cosmos DB master keys to gain full access to the database, allowing data exfiltration, modification, or destruction.
    Investigative actions: Check the identity's actions before and after the key read operation. Verify whether the identity is authorized to access Cosmos DB master keys. Determine if the retrieved keys were used to access or modify data in the Cosmos DB account.
  • Uncommon DLL-sideloading from a logical CD-ROM (ISO) device Medium

    A DLL was loaded by an executable from the same folder on a logical CD-ROM device (ISO).

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Execution (TA0002) Defense Evasion (TA0005) Privilege Escalation (TA0004)
    ATT&CK techniques: Hijack Execution Flow: DLL (T1574.001) User Execution: Malicious File (T1204.002)
    Required data: XDR Agent
    Detector tags: DLL Hijacking Analytics
    Attacker's goals: An attacker is attempting to load untrusted code into trusted contexts to avoid detection or escalate privileges.
    Investigative actions: Investigate the loaded module and verify if it is malicious. Check if the disk is a mounted CD-ROM (for example from an ISO file), and if it contains hidden files and folders. Check the content of an 'autorun.inf' or '*.lnk' files if they exist.
  • Uncommon DotNet module load relationship Informational

    A signed process that usually doesn't use DotNet loaded a common DotNet module.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Defense Evasion (TA0005)
    ATT&CK techniques: Reflective Code Loading (T1620)
    Required data: XDR Agent
    Attacker's goals: Adversaries may reflectively load DotNet code into a process to conceal execution of malicious payloads.
    Investigative actions: Investigate the actor process for potential malicious activity. Check for recently installed services that may load DotNet modules.
  • Uncommon GetClipboardData API function invocation of a possible information stealer Informational

    An unpopular process accessed clipboard content by calling the GetClipboardData API function. This behavior may indicate potential threats such as a keylogger or a RAT.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Collection (TA0009)
    ATT&CK techniques: Clipboard Data (T1115)
    Required data: XDR Agent with eXtended Threat Hunting (XTH)
    Attacker's goals: Attackers can monitor the clipboard as another way for credential gathering or to collect more user data over time for espionage purposes.
    Investigative actions: Check if the process has a user interface (a visible window). Check if the process is a known user application that was updated recently.
  • Uncommon IP Configuration Listing via ipconfig.exe Low

    The 'ipconfig' command is used to display TCP/IP network configuration information and refresh the Dynamic Host Configuration Protocol (DHCP) and Domain Name System (DNS) settings. Adversaries may use the command to discover network configuration details.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Hour
    ATT&CK tactics: Discovery (TA0007)
    ATT&CK techniques: System Network Configuration Discovery (T1016)
    Required data: XDR Agent
    Attacker's goals: Attackers can use the ipconfig command to discover network configuration details.
    Investigative actions: Check whether the initiator process is benign or normal for the host and/or user performing it. Check whether additional discovery commands were executed from the same process.
  • Uncommon Launch Agent persistency was registered or modified Informational 9 variations

    An uncommon Launch Agent persistence mechanism was registered/modified on the system.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Persistence (TA0003)
    ATT&CK techniques: Create or Modify System Process (T1543) Create or Modify System Process: Launch Agent (T1543.001)
    Required data: XDR Agent
    Detector tags: Generic Persistence Analytics
    Attacker's goals: Establish persistent access to the compromised host by registering malicious code.
    Investigative actions: Analyze the persistency item and determine whether it performs any malicious or suspicious actions. Analyze the registered process and determine whether it performs any malicious or suspicious actions. Check the events generated by the process for potential malicious behavior.

    Variations

    Uncommon Launch Agent persistency was registered or modified by a security testing tool

    High overridden

    An uncommon Launch Agent persistence mechanism was registered/modified on the system by a security testing tool. overridden

    Uncommon Launch Agent persistency was registered or modified by a tool with possible web access

    Low overridden

    An uncommon Launch Agent persistence mechanism was registered/modified on the system by a tool with possible web access. overridden

    Uncommon Launch Agent persistency was registered or modified while using a data communication tool

    Low overridden

    An uncommon Launch Agent persistence mechanism was registered/modified on the system while using a data communication tool for persistency registration or as a persistency-triggered execution. overridden

    Uncommon Launch Agent persistency was registered or modified while using osascript

    Low overridden

    An uncommon Launch Agent persistence mechanism was registered/modified on the system while using osascript for persistency registration or as a persistency-triggered execution. overridden

    Uncommon Launch Agent persistency was registered or modified using Plist Buddy with Run-At-Load key

    Low overridden

    An uncommon Launch Agent persistence mechanism was registered/modified on the system using Plist Buddy with Run-At-Load key set to True. overridden

    Uncommon Launch Agent persistency was registered or modified with an uncommon path containing a known vendor name

    Low overridden

    An uncommon Launch Agent persistence mechanism was registered/modified on the system with an uncommon path containing a known vendor name. overridden

    Uncommon Launch Agent persistency was registered or modified with an unusual persistency executable path

    Low overridden

    An uncommon Launch Agent persistence mechanism was registered/modified on the system with an unusual persistency executable path. overridden

    Uncommon Launch Agent persistency was registered or modified by a non validly signed process

    Low overridden

    An uncommon Launch Agent persistence mechanism was registered/modified on the system by a non validly signed process. overridden

    Uncommon Launch Agent persistency was registered or modified by an unsigned process

    Low overridden

    An uncommon Launch Agent persistence mechanism was registered/modified on the system by an unsigned process. overridden

  • Uncommon Launch Daemon persistency was registered or modified Informational 9 variations

    An uncommon Launch Daemon persistence mechanism was registered/modified on the system.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Persistence (TA0003)
    ATT&CK techniques: Create or Modify System Process (T1543) Create or Modify System Process: Launch Daemon (T1543.004)
    Required data: XDR Agent
    Detector tags: Generic Persistence Analytics
    Attacker's goals: Establish persistent access to the compromised host by registering malicious code.
    Investigative actions: Analyze the persistency item and determine whether it performs any malicious or suspicious actions. Analyze the registered process and determine whether it performs any malicious or suspicious actions. Check the events generated by the process for potential malicious behavior.

    Variations

    Uncommon Launch Daemon persistency was registered or modified by a security testing tool

    High overridden

    An uncommon Launch Daemon persistence mechanism was registered/modified on the system by a security testing tool. overridden

    Uncommon Launch Daemon persistency was registered or modified by a tool with possible web access

    Low overridden

    An uncommon Launch Daemon persistence mechanism was registered/modified on the system by a tool with possible web access. overridden

    Uncommon Launch Daemon persistency was registered or modified while using a data communication tool

    Low overridden

    An uncommon Launch Daemon persistence mechanism was registered/modified on the system while using a data communication tool for persistency registration or as a persistency triggered execution. overridden

    Uncommon Launch Daemon persistency was registered or modified while using osascript

    Low overridden

    An uncommon Launch Daemon persistence mechanism was registered/modified on the system while using osascript for persistency registration or as a persistency triggered execution. overridden

    Uncommon Launch Daemon persistency was registered or modified using Plist Buddy with Run-At-Load key

    Low overridden

    An uncommon Launch Daemon persistence mechanism was registered/modified on the system using Plist Buddy with Run-At-Load key set to True. overridden

    Uncommon Launch Daemon persistency was registered or modified with an uncommon path containing a known vendor name

    Low overridden

    An uncommon Launch Daemon persistence mechanism was registered/modified on the system with an uncommon path containing a known vendor name. overridden

    Uncommon Launch Daemon persistency was registered or modified with an unusual persistency executable path

    Low overridden

    An uncommon Launch Daemon persistence mechanism was registered/modified on the system with an unusual persistency executable path. overridden

    Uncommon Launch Daemon persistency was registered or modified by a non validly signed process

    Low overridden

    An uncommon Launch Daemon persistence mechanism was registered/modified on the system by a non validly signed process. overridden

    Uncommon Launch Daemon persistency was registered or modified by an unsigned process

    Low overridden

    An uncommon Launch Daemon persistence mechanism was registered/modified on the system by an unsigned process. overridden

  • Uncommon Linux process communication to a rare external host Informational 6 variations

    An uncommon process is connecting to an external domain that is rarely accessed within the organization. This connection pattern is consistent with malware initiating connection to its command and control server.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Command and Control (TA0011)
    ATT&CK techniques: Application Layer Protocol (T1071)
    Required data: XDR Agent
    Detector tags: Abnormal Communication Analytics
    Attacker's goals: Communicate with malware running on your network to control malware activities, perform software updates on the malware, or to take inventory of infected machines.
    Investigative actions: Identify the process contacting the remote domain and determine whether the traffic is malicious. Look for other endpoints on your network that are alsocontacting the suspicious domain. Inspect the domain or URL for suspicious indicators or its presence in malicious reputation lists.

    Variations

    Uncommon Linux process communication to a rare external host by an automated penetration testing tool

    Medium overridden

    An uncommon process is connecting to an external domain that is rarely accessed within the organization. This connection pattern is consistent with malware initiating connection to its command and control server. overridden

    Uncommon Linux process communication to a rare external host involving a code sharing website

    Low overridden

    An uncommon process is connecting to an external domain that is rarely accessed within the organization. This connection pattern is consistent with malware initiating connection to its command and control server. overridden

    Uncommon Linux process communication to a rare external host involving a low-prevalence process connecting to a rare Top-Level Domain

    Low overridden

    An uncommon process is connecting to an external domain that is rarely accessed within the organization. This connection pattern is consistent with malware initiating connection to its command and control server. overridden

    Uncommon Linux process communication to a rare external host with an external IP in the command line

    Low overridden

    An uncommon process is connecting to an external domain that is rarely accessed within the organization. This connection pattern is consistent with malware initiating connection to its command and control server. overridden

    Uncommon Linux process communication to a rare external host using a data transfer tool

    Low overridden

    An uncommon process is connecting to an external domain that is rarely accessed within the organization. This connection pattern is consistent with malware initiating connection to its command and control server. overridden

    Uncommon Linux process communication to a rare external host identified as global anomaly

    Low overridden

    An uncommon process is connecting to an external domain that is rarely accessed within the organization. This connection pattern is consistent with malware initiating connection to its command and control server. overridden

  • Uncommon Linux remote shell command execution Informational 15 variations

    An unusual process execution of a shell command on Linux from a remote source. This action may indicate possible exploitation or shell command execution via a backdoor.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Execution (TA0002) Lateral Movement (TA0008)
    ATT&CK techniques: Command and Scripting Interpreter: Unix Shell (T1059.004) Command and Scripting Interpreter (T1059) Remote Services (T1021)
    Required data: XDR Agent
    Detector tags: Shell Analytics
    Attacker's goals: An attacker may attempt to execute a malicious shell command on the system.
    Investigative actions: Check whether the executing process is benign and if this was a desired behavior as part of its normal execution flow. Check the executed shell command (and possible child processes) for malicious actions.

    Variations

    Uncommon Linux remote shell command execution, possibly running LinPEAS

    High overridden

    An unusual process execution of a shell command on Linux from a remote source. This action may indicate possible exploitation or shell command execution via a backdoor. overridden

    Uncommon Linux remote shell command execution using an exploitation tool

    High overridden

    An unusual process execution of a shell command on Linux from a remote source. This action may indicate possible exploitation or shell command execution via a backdoor. overridden

    Uncommon Linux remote shell command execution executing a reverse interactive shell

    Medium overridden

    An unusual process execution of a shell command on Linux from a remote source. This action may indicate possible exploitation or shell command execution via a backdoor. overridden

    Uncommon Linux remote shell command execution downloading a shell script

    Medium overridden

    An unusual process execution of a shell command on Linux from a remote source. This action may indicate possible exploitation or shell command execution via a backdoor. overridden

    Uncommon Linux remote shell command execution disabling firewall

    Low overridden

    An unusual process execution of a shell command on Linux from a remote source. This action may indicate possible exploitation or shell command execution via a backdoor. overridden

    Uncommon Linux remote shell command execution taking a screenshot

    Low overridden

    An unusual process execution of a shell command on Linux from a remote source. This action may indicate possible exploitation or shell command execution via a backdoor. overridden

    Uncommon Linux remote shell command execution possibly running from an XZ backdoor

    Low overridden

    An unusual process execution of a shell command on Linux from a remote source. This action may indicate possible exploitation or shell command execution via a backdoor. overridden

    Uncommon Linux remote shell command execution running as root

    Low overridden

    An unusual process execution of a shell command on Linux from a remote source. This action may indicate possible exploitation or shell command execution via a backdoor. overridden

    Uncommon Linux remote shell command execution setting a scheduled task

    Low overridden

    An unusual process execution of a shell command on Linux from a remote source. This action may indicate possible exploitation or shell command execution via a backdoor. overridden

    Uncommon Linux remote shell command execution running a process kill command

    Low overridden

    An unusual process execution of a shell command on Linux from a remote source. This action may indicate possible exploitation or shell command execution via a backdoor. overridden

    Uncommon Linux remote shell command execution loading a kernel module

    Informational overridden

    An unusual process execution of a shell command on Linux from a remote source. This action may indicate possible exploitation or shell command execution via a backdoor. overridden

    Uncommon Linux remote shell command execution via non-SSH or SSH on a non-standard port

    Informational overridden

    An unusual process execution of a shell command on Linux from a remote source. This action may indicate possible exploitation or shell command execution via a backdoor. overridden

    Uncommon Linux remote shell command execution running a network tool

    Informational overridden

    An unusual process execution of a shell command on Linux from a remote source. This action may indicate possible exploitation or shell command execution via a backdoor. overridden

    Uncommon Linux remote shell command execution trying to gather information about the system

    Informational overridden

    An unusual process execution of a shell command on Linux from a remote source. This action may indicate possible exploitation or shell command execution via a backdoor. overridden

    Uncommon Linux remote shell command execution, possibly granting file execution permissions

    Informational overridden

    An unusual process execution of a shell command on Linux from a remote source. This action may indicate possible exploitation or shell command execution via a backdoor. overridden

  • Uncommon Linux shell command execution Informational 15 variations

    An unusual process execution of a shell command on Linux. This action may indicate possible exploitation or shell command execution via a backdoor.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Execution (TA0002)
    ATT&CK techniques: Command and Scripting Interpreter: Unix Shell (T1059.004) Command and Scripting Interpreter (T1059)
    Required data: XDR Agent
    Detector tags: Shell Analytics
    Attacker's goals: An attacker may attempt to execute a malicious shell command on the system.
    Investigative actions: Check whether the executing process is benign and if this was a desired behavior as part of its normal execution flow. Check the executed shell command (and possible child processes) for malicious actions.

    Variations

    Uncommon Linux shell command execution by a BAS solution

    High overridden

    An unusual process execution of a shell command on Linux. This action may indicate possible exploitation or shell command execution via a backdoor. overridden

    Uncommon Linux shell command execution disabling firewall

    High overridden

    An unusual process execution of a shell command on Linux. This action may indicate possible exploitation or shell command execution via a backdoor. overridden

    Uncommon Linux shell command execution, possibly running LinPEAS

    High overridden

    An unusual process execution of a shell command on Linux. This action may indicate possible exploitation or shell command execution via a backdoor. overridden

    Uncommon Linux shell command execution using exploitation tool

    High overridden

    An unusual process execution of a shell command on Linux. This action may indicate possible exploitation or shell command execution via a backdoor. overridden

    Uncommon Linux shell command execution taking a screenshot

    Low overridden

    An unusual process execution of a shell command on Linux. This action may indicate possible exploitation or shell command execution via a backdoor. overridden

    Uncommon Linux shell command execution trying to gather information about the system

    Low overridden

    An unusual process execution of a shell command on Linux. This action may indicate possible exploitation or shell command execution via a backdoor. overridden

    Uncommon Linux shell command execution loading a kernel module

    Low overridden

    An unusual process execution of a shell command on Linux. This action may indicate possible exploitation or shell command execution via a backdoor. overridden

    Uncommon Linux shell command execution, possibly granting file execution permissions

    Low overridden

    An unusual process execution of a shell command on Linux. This action may indicate possible exploitation or shell command execution via a backdoor. overridden

    Uncommon Linux shell command execution running a network tool

    Low overridden

    An unusual process execution of a shell command on Linux. This action may indicate possible exploitation or shell command execution via a backdoor. overridden

    Uncommon Linux shell command execution setting a scheduled task

    Low overridden

    An unusual process execution of a shell command on Linux. This action may indicate possible exploitation or shell command execution via a backdoor. overridden

    Uncommon Linux shell command execution running a process kill command

    Low overridden

    An unusual process execution of a shell command on Linux. This action may indicate possible exploitation or shell command execution via a backdoor. overridden

    Uncommon Linux shell command execution with su/sudo elevation

    Informational overridden

    An unusual process execution of a shell command on Linux. This action may indicate possible exploitation or shell command execution via a backdoor. overridden

    Uncommon Linux shell command execution accessing history (e.g. bash history or login records)

    Informational overridden

    An unusual process execution of a shell command on Linux. This action may indicate possible exploitation or shell command execution via a backdoor. overridden

    Uncommon Linux shell command execution from a scripting language interpreter

    Informational overridden

    An unusual process execution of a shell command on Linux. This action may indicate possible exploitation or shell command execution via a backdoor. overridden

    Uncommon Linux shell command execution executed from within a web server

    Informational overridden

    An unusual process execution of a shell command on Linux. This action may indicate possible exploitation or shell command execution via a backdoor. overridden

  • Uncommon Managed Object Format (MOF) compiler usage Informational

    The mofcomp.exe WMI MOF compiled is used to compile code into the WMI repository that in turn may enable attackers to run scheduled or triggered code from the context of a Microsoft-signed binary.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Hour
    ATT&CK tactics: Persistence (TA0003)
    ATT&CK techniques: Event Triggered Execution: Windows Management Instrumentation Event Subscription (T1546.003)
    Required data: XDR Agent
    Attacker's goals: Run code via triggers from the context of the WMI executor.
    Investigative actions: Verify if the executing process is suspicious. Check if the MOF file being compiled has any malicious indicators within it.
  • Uncommon NtWriteVirtualMemoryRemote API invocation with a PE header buffer Low 4 variations

    A process wrote a PE header to another process by calling the NtWriteVirtualMemoryRemote API function.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Defense Evasion (TA0005) Privilege Escalation (TA0004)
    ATT&CK techniques: Process Injection: Portable Executable Injection (T1055.002)
    Required data: XDR Agent with eXtended Threat Hunting (XTH)
    Detector tags: Injection Analytics
    Attacker's goals: Gain code execution on the host in the context of another process.
    Investigative actions: Investigate the acting process for other malicious activities. Check if the target process was injected and for anomalies in its behavior after this event.

    Variations

    Uncommon NtWriteVirtualMemoryRemote API invocation with a PE header buffer from an office process

    High overridden

    An office process wrote a PE header to another process by calling the NtWriteVirtualMemoryRemote API function. overridden

    Uncommon NtWriteVirtualMemoryRemote API invocation with a PE header buffer from an injected thread

    Medium overridden

    An injected thread wrote a PE header to another process by calling the NtWriteVirtualMemoryRemote API function. overridden

    Uncommon NtWriteVirtualMemoryRemote API invocation with a PE header buffer from a LOLBIN process

    Medium overridden

    A LOLBIN process wrote a PE header to another process by calling the NtWriteVirtualMemoryRemote API function. overridden

    Uncommon NtWriteVirtualMemoryRemote API invocation with a PE header buffer from an unsigned process

    Medium overridden

    An unsigned process wrote a PE header to another process by calling the NtWriteVirtualMemoryRemote API function. overridden

  • Uncommon PowerShell commands used to create or alter scheduled task parameters Low

    Attackers may create or alter scheduled task parameters to gain higher privileges or persistence on the system.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Persistence (TA0003)
    ATT&CK techniques: Scheduled Task/Job: Scheduled Task (T1053.005)
    Required data: XDR Agent with eXtended Threat Hunting (XTH)
    Attacker's goals: Create a new scheduled task or alter an existing one to gain persistence in the system or to gain higher privileges.
    Investigative actions: Examine the PowerShell command to identify suspicious scheduled task creation or modification. Inspect the system for suspicious activity that is triggered by a scheduled task.
  • Uncommon RDP connection Informational

    RDP is used by attackers to laterally move to new hosts. Standard processes do not usually implement RDP on their own, and attackers might inject or tunnel using a non-standard process.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Hour
    ATT&CK tactics: Lateral Movement (TA0008)
    ATT&CK techniques: Remote Services: Remote Desktop Protocol (T1021.001)
    Required data: XDR Agent
    Detector tags: Enhanced RDP Analytics
    Attacker's goals: Use an account that was possibly compromised to gain access to the network.
    Investigative actions: Validate if the process is a legitimate IT software. Verify if the process is known to be malicious. Look into actions done on the remote host.
  • Uncommon SQL like command line Informational 3 variations

    Uncommon SQL query in command line of an executed process.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Credential Access (TA0006)
    ATT&CK techniques: Unsecured Credentials: Credentials In Files (T1552.001)
    Required data: XDR Agent
    Attacker's goals: An attacker may use SQL queries to steal information stored at the target databases.
    Investigative actions: Check if the CGO (Causality Group Owner) is known for running SQL queries in the organization.

    Variations

    Uncommon SQL like command line executed by a remote actor

    Medium overridden

    Uncommon SQL query in command line of a process which executed remotely. overridden

    Uncommon SQL like command line executed by an RMM tool

    Medium overridden

    Uncommon SQL query in command line of a process executed by a Remote Monitoring & Management tool. overridden

    Uncommon SQL like command line executed by an uncommon CGO

    Low overridden

    Uncommon SQL query in command line of an executed process. overridden

  • Uncommon SSH session was established Low 14 variations

    An uncommon SSH session was established.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Command and Control (TA0011)
    ATT&CK techniques: Application Layer Protocol (T1071) Non-Standard Port (T1571)
    Required data: Palo Alto Networks Firewall traffic Logs XDR Agent Third-Party Firewalls
    Detector tags: NDR Lateral Movement Analytics
    Attacker's goals: Attackers may use SSH or any similar utility to create a network tunnel to allow an attacker to covertly connect to an internal host.
    Investigative actions: Review the external IP/domain using known intelligence tools. Investigate the causality of the process and its user ID to find uncommon behaviors. Search for processes or files that were created by this SSH instance.

    Variations

    An Uncommon SSH session was established using a rare server HASSH for the ssh server

    Low overridden

    An Uncommon SSH session was established using a rare server HASSH for the ssh server. overridden

    An Uncommon SSH session was established using a rare client HASSH for the agent

    Low overridden

    An uncommon SSH session was established using a rare client HASSH for the agent. overridden

    An Uncommon SSH session was established using a rare request banner for the agent

    Low overridden

    An Uncommon SSH session was established using a rare request banner for the agent. overridden

    An Uncommon SSH session was established using a rare Response banner for the ssh server

    Low overridden

    An Uncommon SSH session was established using a rare Response banner for the ssh server. overridden

    An Uncommon SSH session was established using a rare Response banner

    Low overridden

    An Uncommon SSH session was established using a rare Response banner. overridden

    An Uncommon SSH session was established using a rare request banner

    Low overridden

    An Uncommon SSH session was established using a rare request banner. overridden

    An Uncommon SSH session was established using a rare Client HASSH

    Low overridden

    An uncommon SSH session was established using a rare client HASSH. overridden

    An Uncommon SSH session was established using a rare Server HASSH

    Low overridden

    An Uncommon SSH session was established using a rare Server HASSH. overridden

    A suspicious SSH session was established

    Low overridden

    A suspicious SSH session was established to a globally rare external IP using a nonstandard SSH port. overridden

    An Uncommon SSH session was established to a rare IP address

    Low overridden

    An uncommon SSH session was established to a rare remote IP address. overridden

    An Uncommon SSH session was established using a nonstandard SSH port

    Low overridden

    An uncommon SSH session was established with a destination port using a nonstandard SSH port. overridden

    Uncommon SSH session was established to a rare internal IP

    Low overridden

    An uncommon SSH session was established to a rare internal IP. overridden

    Uncommon SSH session was established that involved a higher than usual volume

    Low overridden

    Uncommon SSH session was established that involved a higher than usual volume. overridden

    Uncommon SSH session was established to an internal IP

    Informational overridden

    An uncommon SSH session was established to an internal IP. overridden

  • Uncommon Security Support Provider (SSP) registered via a registry key Low

    Security Support Provider (SSP) exposes a number of callbacks to be invoked during certain authentication and authorization events. An attacker may register SSP to try and gain access to clear text passwords.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Privilege Escalation (TA0004)
    ATT&CK techniques: Boot or Logon Autostart Execution: Security Support Provider (T1547.005)
    Required data: XDR Agent with eXtended Threat Hunting (XTH)
    Attacker's goals: Gain clear text passwords and persistency in the network.
    Investigative actions: Audit the specific key values to verify that the additional values are trusted.
  • Uncommon Service Create/Config Medium

    The Service Control command (sc.exe) is used to create, start, stop, query, or delete Windows services. Adversaries may attempt to use the command to execute and persist a binary, command, or script.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Hour
    ATT&CK tactics: Execution (TA0002)
    ATT&CK techniques: System Services: Service Execution (T1569.002)
    Required data: XDR Agent
    Detector tags: Malicious Service Analytics
    Attacker's goals: Evading security controls and possibly persisting malware.
    Investigative actions: Check whether the service created, or the configuration change to an existing service, is benign or normal for the host and/or user performing it.
  • Uncommon SetWindowsHookEx API invocation of a possible keylogger Medium

    A process installed a Windows desktop hook by calling the SetWindowsHookEx API function with an unpopular module. This behavior is commonly seen in keyloggers.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Credential Access (TA0006) Collection (TA0009)
    ATT&CK techniques: Input Capture: Keylogging (T1056.001)
    Required data: XDR Agent with eXtended Threat Hunting (XTH)
    Attacker's goals: Attackers can monitor keyboard events as another way for credential gathering or to collect more user data over time for espionage purposes.
    Investigative actions: Check if the process has a user interface (a visible window). Check if the process has an option to set or modify keyboard hot-keys. Check if the process is part of a remote control tool. Check if the process is a known user application that was updated recently. Check if the process is built with AutoHotkey and is known to the user.* If the process is a scripting engine or a hosting executable, check the actor process command line. Investigate the endpoint if the process writes files to disk.
  • Uncommon URL domain(s) in your organization detected in email Informational Email 3 variations

    We have identified unpopular domain(s) in URL(s) within this email.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Initial Access (TA0001) Execution (TA0002)
    ATT&CK techniques: Phishing (T1566) User Execution (T1204)
    Required data: Microsoft 365 Emails
    Detector tags: Malicious URLs
    Attacker's goals: Trick the user into engaging with a URL(s), aiming to extract information or establish access to the network.
    Investigative actions: Examine the sender's IP address and reputation. Verify whether the sender's IP address has appeared in different log sources before and if it is recognizable. If the message contains attachments or links, scrutinize them for any suspicious indications. Monitor further actions taken, such as file downloads or access to potentially malicious links.

    Variations

    External email with a first-seen URL domain(s) in your organization in the last 30 days

    Informational overridden

    We have identified unpopular domain(s) in URL(s) within this email. overridden

    Internal email with a first-seen URL domain(s) in your organization in the last 30 days

    Informational overridden

    We have identified unpopular domain(s) in URL(s) within this email. overridden

    Outbound email with a first-seen URL domain(s) in your organization in the last 30 days

    Informational overridden

    We have identified unpopular domain(s) in URL(s) within this email. overridden

  • Uncommon VNC server communication Low 4 variations

    Uncommon VNC server network traffic was observed.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Command and Control (TA0011) Lateral Movement (TA0008)
    ATT&CK techniques: Remote Access Tools (T1219) Remote Services: VNC (T1021.005)
    Required data: XDR Agent
    Attacker's goals: Accessing a remote machine with full interactive graphic interface capabilities.
    Investigative actions: Check if the product usage is approved. Check if it was executed remotely or locally.

    Variations

    Uncommon VNC scanning activity detected from a scanning tool

    Medium overridden

    An uncommon VNC scanning network traffic was observed from a scanning tool. overridden

    Uncommon VNC server communication from an unmanaged previously unseen external host

    Low overridden

    Uncommon VNC server network traffic was observed from an unmanaged, previously unseen external host. overridden

    Partially uncommon VNC server communication

    Informational overridden

    Uncommon VNC server network traffic was observed. overridden

    Uncommon VNC server connection

    Informational overridden

    An uncommon VNC Server network connection was observed. overridden

  • Uncommon WPAD queries Informational 3 variations

    There were multiple attempts to access WPAD resources by a single host in your network. This may indicate a malicious activity.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    1 Hour
    Deduplication:
    1 Day
    ATT&CK tactics: Credential Access (TA0006)
    ATT&CK techniques: Adversary-in-the-Middle (T1557)
    Required data: Palo Alto Networks Firewall EAL Logs XDR Agent
    Attacker's goals: Attackers may attempt to move laterally over the network by exploiting problems in WPAD.
    Investigative actions: Verify that the source host is legitimate.* Examine the legitimacy of the application that produced this uncommon WPAD. Examine the parent process of this application.

    Variations

    Uncommon WPAD queries to a external domain

    Informational overridden

    There were multiple attempts to access WPAD resources by a single host in your network. This may indicate a malicious activity. overridden

    Suspicious WPAD queries

    Low overridden

    There were multiple attempts to access WPAD resources by a single host in your network. This may indicate a malicious activity. overridden

    Uncommon WPAD queries using an uncommon port

    Informational overridden

    There were multiple attempts to access WPAD resources by a single host in your network. This may indicate a malicious activity. overridden

  • Uncommon access to /etc/passwd Informational 11 variations

    A process made an uncommon attempt to access /etc/passwd.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Discovery (TA0007) Credential Access (TA0006)
    ATT&CK techniques: File and Directory Discovery (T1083) System Service Discovery (T1007) System Owner/User Discovery (T1033) System Information Discovery (T1082) Account Discovery (T1087) Account Discovery: Local Account (T1087.001) OS Credential Dumping (T1003)
    Required data: XDR Agent with eXtended Threat Hunting (XTH)
    Detector tags: EDR Discovery Analytics, Credentials Grabbing Analytics
    Attacker's goals: Attackers may attempt to access sensitive files to steal credentials, perform reconnaissance on system configurations and users, and find pathways for lateral movement.
    Investigative actions: Review the event's context - examine the process, its command line, and its origin to gain a comprehensive understanding of the anomalous access.* Assess the behavior's legitimacy: Given that this is an uncommon event, determine if this file access is an expected and authorized behavior for the actor process.

    Variations

    Uncommon access to /etc/passwd by a security testing tool

    Medium overridden

    A process made an uncommon attempt to access /etc/passwd. overridden

    Uncommon access to /etc/passwd by a potentially known credential dumper or enumeration script

    Medium overridden

    A process made an uncommon attempt to access /etc/passwd. overridden

    Uncommon access to /etc/passwd by a potential Webshell

    Medium overridden

    A process made an uncommon attempt to access /etc/passwd. overridden

    Uncommon link creation to /etc/passwd

    Low overridden

    A process made an uncommon attempt to access /etc/passwd. overridden

    Uncommon access to /etc/passwd with both /etc/passwd and /etc/shadow in the command line

    Low overridden

    A process made an uncommon attempt to access /etc/passwd. overridden

    Uncommon access to /etc/passwd, involving a network utility

    Low overridden

    A process made an uncommon attempt to access /etc/passwd. overridden

    Uncommon access to /etc/passwd from temporary or world writable directories

    Low overridden

    A process made an uncommon attempt to access /etc/passwd. overridden

    Uncommon access to /etc/passwd with additional sensitive files in the command line

    Low overridden

    A process made an uncommon attempt to access /etc/passwd. overridden

    Uncommon access to /etc/passwd via a new inline bash script

    Low overridden

    A process made an uncommon attempt to access /etc/passwd. overridden

    Uncommon access to /etc/passwd using an interactive binary

    Low overridden

    A process made an uncommon attempt to access /etc/passwd. overridden

    Uncommon access to /etc/passwd using an interactive shell

    Low overridden

    A process made an uncommon attempt to access /etc/passwd. overridden

  • Uncommon access to Microsoft Teams cookies files Informational Identity Analytics 1 variation

    Sensitive Microsoft Teams cookies files were accessed.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    10 Minutes
    Deduplication:
    1 Day
    ATT&CK tactics: Credential Access (TA0006)
    ATT&CK techniques: Credentials from Password Stores (T1555) Steal Application Access Token (T1528)
    Required data: XDR Agent with eXtended Threat Hunting (XTH)
    Detector tags: Microsoft Teams
    Attacker's goals: Attacker may access credentials files and steal application access tokens to gain remote access.
    Investigative actions: Investigate the actor process to determine if it was used for legitimate purposes or malicious activity. Review the host for any additional unusual activity. Investigate the Graph API calls followed by the user that might be related.

    Variations

    Suspicious uncommon access to Microsoft Teams cookies files

    Low overridden

    Sensitive Microsoft Teams cookies files were accessed by a suspicious process. overridden

  • Uncommon access to Microsoft Teams credential files Low 1 variation

    Sensitive Microsoft Teams credential files were accessed.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Credential Access (TA0006)
    ATT&CK techniques: Unsecured Credentials (T1552)
    Required data: XDR Agent with eXtended Threat Hunting (XTH)
    Attacker's goals: Accessing these files is done by attackers to collect user credentials.
    Investigative actions: Investigate the actor process to determine if it was used for legitimate purposes or malicious activity.

    Variations

    Uncommon access to Microsoft Teams credential files by an unsigned and unpopular process

    Low overridden

    Sensitive Microsoft Teams credential files were accessed. by an unsigned and unpopular process. overridden

  • Uncommon access to cloud platforms' sensitive files by a scripting engine Informational 1 variation

    A scripting engine has accessed sensitive cloud platforms' files.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Credential Access (TA0006)
    ATT&CK techniques: Credentials from Password Stores (T1555)
    Required data: XDR Agent with eXtended Threat Hunting (XTH)
    Attacker's goals: Gain access/control over internal cloud platforms or repositories.
    Investigative actions: Investigate if the behavior is known to the user or part of known product's procedure. Investigate if the actor processes command line contains malicious indicators or a script file.

    Variations

    Uncommon access to cloud platforms' sensitive files by an uncommon script or utility

    Low overridden

    A scripting engine has accessed sensitive cloud platforms' files. overridden

  • Uncommon attempt at discovering a sensitive file Informational 8 variations

    A process made an uncommon attempt to access a file that may contain sensitive information.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Discovery (TA0007)
    ATT&CK techniques: File and Directory Discovery (T1083) Process Discovery (T1057) System Service Discovery (T1007) System Network Configuration Discovery (T1016) System Owner/User Discovery (T1033) System Network Connections Discovery (T1049) System Information Discovery (T1082)
    Required data: XDR Agent with eXtended Threat Hunting (XTH)
    Detector tags: EDR Discovery Analytics
    Attacker's goals: Attackers may attempt to access sensitive files to steal credentials, perform reconnaissance on system configurations and users, and find pathways for lateral movement.
    Investigative actions: Review the event's context - examine the process, its command line, and its origin to gain a comprehensive understanding of the anomalous access.* Assess the behavior's legitimacy: Given that this is an uncommon event, determine if this file access is an expected and authorized behavior for the actor process.

    Variations

    Uncommon attempt at discovering /etc/hosts

    Informational overridden

    A process made an uncommon attempt to access a file that may contain sensitive information. overridden

    Uncommon attempt at discovering a sensitive file by a security testing tool

    Medium overridden

    A process made an uncommon attempt to access a file that may contain sensitive information. overridden

    Uncommon attempt at discovering a sensitive file by a potentially known credential dumper or enumeration script

    Medium overridden

    A process made an uncommon attempt to access a file that may contain sensitive information. overridden

    Uncommon attempt at discovering a sensitive file by a potential Webshell

    Low overridden

    A process made an uncommon attempt to access a file that may contain sensitive information. overridden

    Uncommon attempt at discovering a sensitive file by a script that was executed by a rare causality

    Low overridden

    A process made an uncommon attempt to access a file that may contain sensitive information. overridden

    Uncommon attempt at discovering a sensitive file from temporary or world writable directories

    Low overridden

    A process made an uncommon attempt to access a file that may contain sensitive information. overridden

    Uncommon attempt at discovering a sensitive file by a rare process that was executed by cron

    Low overridden

    A process made an uncommon attempt to access a file that may contain sensitive information. overridden

    Uncommon attempt at discovering a sensitive file by a non-GTFOBIN process

    Low overridden

    A process made an uncommon attempt to access a file that may contain sensitive information. overridden

  • Uncommon attempt at grabbing credentials from a sensitive file Informational 8 variations

    A process made an uncommon attempt to access a file that may contain sensitive information.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Credential Access (TA0006) Discovery (TA0007)
    ATT&CK techniques: OS Credential Dumping (T1003) Unsecured Credentials: Credentials In Files (T1552.001) Unsecured Credentials (T1552) Credentials from Password Stores (T1555) Account Discovery (T1087)
    Required data: XDR Agent with eXtended Threat Hunting (XTH)
    Detector tags: Credentials Grabbing Analytics
    Attacker's goals: Attackers may attempt to access sensitive files to steal credentials, perform reconnaissance on system configurations and users, and find pathways for lateral movement.
    Investigative actions: Review the event's context - examine the process, its command line, and its origin to gain a comprehensive understanding of the anomalous access.* Assess the behavior's legitimacy: Given that this is an uncommon event, determine if this file access is an expected and authorized behavior for the actor process.

    Variations

    Uncommon attempt at grabbing credentials from a sensitive file by a security testing tool

    High overridden

    A process made an uncommon attempt to access a file that may contain sensitive information. overridden

    Uncommon attempt at grabbing credentials from a sensitive file by a potentially known credential dumper or enumeration script

    Medium overridden

    A process made an uncommon attempt to access a file that may contain sensitive information. overridden

    Uncommon attempt at grabbing credentials from an SSH private key

    Low overridden

    A process made an uncommon attempt to access a file that may contain sensitive information. overridden

    Uncommon attempt at grabbing credentials from a sensitive file by a potential Webshell

    Low overridden

    A process made an uncommon attempt to access a file that may contain sensitive information. overridden

    Uncommon attempt at grabbing credentials from a sensitive file by a script that was executed by a rare causality

    Low overridden

    A process made an uncommon attempt to access a file that may contain sensitive information. overridden

    Uncommon attempt at grabbing credentials from a sensitive file from temporary or world writable directories

    Low overridden

    A process made an uncommon attempt to access a file that may contain sensitive information. overridden

    Uncommon attempt at grabbing credentials from a sensitive file by a rare process that was executed by cron

    Low overridden

    A process made an uncommon attempt to access a file that may contain sensitive information. overridden

    Uncommon attempt at grabbing credentials from a sensitive file by a non-GTFOBIN process

    Low overridden

    A process made an uncommon attempt to access a file that may contain sensitive information. overridden

  • Uncommon attempt to clear shell history Low 1 variation

    An attempt to clear or manipulate shell history files was detected.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Defense Evasion (TA0005)
    ATT&CK techniques: Indicator Removal (T1070)
    Required data: XDR Agent
    Attacker's goals: Attackers may clear or modify shell history files to remove traces of their activities.
    Investigative actions: Investigate the user and process that executed the command. Examine other related activities on the host to understand the context of this action.

    Variations

    Globally uncommon attempt to clear shell history

    Medium overridden

    An attempt to clear or manipulate shell history files was detected. overridden

  • Uncommon browser extension loaded Informational

    An uncommon browser extension was loaded by a Chromium-based browser.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Persistence (TA0003)
    ATT&CK techniques: Software Extensions: Browser Extensions (T1176.001)
    Required data: XDR Agent with eXtended Threat Hunting (XTH)
    Detector tags: Chromium Extensions Analytics
    Attacker's goals: Gain persistency on a machine and steal sensitive browsing data.
    Investigative actions: Investigate the extension and how it was loaded. Check if this extension is currently present at the relevant extensions web store by looking up for its extension ID.
  • Uncommon cloud CLI tool usage Informational Cloud 4 variations

    An uncommon execution of a cloud CLI tool.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    5 Days
    ATT&CK tactics: Execution (TA0002)
    ATT&CK techniques: Command and Scripting Interpreter: Cloud API (T1059.009)
    Required data: XDR Agent
    Attacker's goals: Abuse cloud APIs to execute malicious commands.
    Investigative actions: Check what cloud CLI commands were executed.* Verify which cloud resources may have been affected.

    Variations

    Uncommon cloud CLI tool usage within a web server pod

    Low overridden

    An uncommon execution of a cloud CLI tool. overridden

    Uncommon cloud CLI tool usage within a web server

    Low overridden

    An uncommon execution of a cloud CLI tool. overridden

    Uncommon cloud CLI tool usage within a cloud instance

    Low overridden

    An uncommon execution of a cloud CLI tool. overridden

    Uncommon cloud CLI tool usage within a Kubernetes pod

    Informational overridden

    An uncommon execution of a cloud CLI tool. overridden

  • Uncommon communication to an instant messaging server Informational 2 variations

    A rare communication between a process to a known instant messaging server.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Command and Control (TA0011)
    ATT&CK techniques: Web Service (T1102)
    Required data: XDR Agent
    Attacker's goals: Data exfiltration or attack tool staging through a trusted service.
    Investigative actions: Examine the legitimacy of the application that made the communication with the provider's server. Examine the parent process of this application. Check for anomalies regarding the time frame where the communication occurred.

    Variations

    Uncommon communication to an instant messaging server by a suspicious process

    Low overridden

    A rare communication by a suspicious process to a known instant messaging server. overridden

    Uncommon communication to an instant messaging server by an uncommon scripting engine execution

    Low overridden

    A rare communication by an uncommon execution of a scripting engine to a known instant messaging server. overridden

  • Uncommon creation or access operation of sensitive shadow copy Low 2 variations

    An uncommon creation or access of a sensitive Shadow Copy volume path.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Credential Access (TA0006)
    ATT&CK techniques: OS Credential Dumping (T1003)
    Required data: XDR Agent with eXtended Threat Hunting (XTH)
    Attacker's goals: Attackers may try to copy sensitive data or dump OS credentials from the host file system by using Shadow Copy volume utilities.
    Investigative actions: Verify if the shadow copy operation is part of an IT activity. Look for other hosts performing the same shadow copy event with similar causality process behavior.* Inspect the causality process and its characteristics as they appear on other hosts.

    Variations

    Uncommon creation or access operation of sensitive shadow copy by a remote actor

    Low overridden

    An uncommon creation or access of a sensitive Shadow Copy volume path. overridden

    Uncommon creation or access operation of sensitive shadow copy by a high-risk process

    High overridden

    An uncommon creation or access of a sensitive Shadow Copy volume path by a high-risk process. overridden

  • Uncommon driver loaded Low 3 variations

    An uncommon driver loaded which may be an attempt to kill the EDR or install rootkit.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Defense Evasion (TA0005)
    ATT&CK techniques: Rootkit (T1014)
    Required data: XDR Agent
    Attacker's goals: Install rootkit to gain kernel-level to gain full control over the machine or disable security products.
    Investigative actions: Investigate which process created the driver or how it has been loaded.

    Variations

    Uncommon driver loaded by a Web server process

    High overridden

    An uncommon driver loaded which may be an attempt to kill the EDR or install rootkit by a Web server process. overridden

    Globally rare and unsigned driver loaded

    Medium overridden

    Globally rare and unsigned driver loaded. overridden

    Uncommon driver with a globally rare vendor loaded as a service

    Medium overridden

    An uncommon driver loaded which may be an attempt to kill the EDR or install rootkit. overridden

  • Uncommon execution of ODBCConf Low 1 variation

    Attackers may abuse the Odbcconf.exe Windows utility to proxy the execution of malicious DLL files.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Defense Evasion (TA0005)
    ATT&CK techniques: System Binary Proxy Execution: Odbcconf (T1218.008)
    Required data: XDR Agent
    Attacker's goals: Execute arbitrary code or load malicious DLL modules undetected within Microsoft signed program from Microsoft signed process.
    Investigative actions: Check the execution command-line, in case of 'REGSVR' points to a DLL, then check it. If the command-line contains '/f' argument (for script file) check the content of the script.

    Variations

    Uncommon execution of ODBCConf to load dll directly

    High overridden

    Attackers may abuse the Odbcconf.exe Windows utility to proxy the execution of malicious DLL files. overridden

  • Uncommon file access over WebDAV Low 1 variation

    Uncommon file access over WebDAV.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Command and Control (TA0011)
    ATT&CK techniques: Application Layer Protocol: Web Protocols (T1071.001)
    Required data: XDR Agent with eXtended Threat Hunting (XTH)
    Attacker's goals: Threat actors may use the WebDAV to blend in existing network traffic.
    Investigative actions: Investigate the process {actor_process_image_name} which tried to access the remote file. Investigate the remote host {webdav_dst_from_file_event}.

    Variations

    High-risk file read over WebDAV by a LOLBIN process

    High overridden

    High-risk file read over WebDAV by a LOLBIN process. overridden

  • Uncommon increase in Azure Microsoft Graph API request sizes Informational Cloud 3 variations

    An identity executed multiple Microsoft Graph actions, leading to an uncommon increase in API request sizes.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    10 Minutes
    Deduplication:
    5 Days
    ATT&CK tactics: Exfiltration (TA0010)
    ATT&CK techniques: Exfiltration Over Alternative Protocol (T1048)
    Required data: Azure Audit Log Microsoft Graph Logs
    Detector tags: Microsoft Graph Activity Logs
    Attacker's goals: Exfiltrate data over Microsoft Graph API.
    Investigative actions: Check the identity's role designation in the organization. Check if there are additional calls executed by the identity.

    Variations

    Unusual Azure high-volume data transfer

    Medium overridden

    An identity executed multiple Microsoft Graph actions, leading to an uncommon increase in API request sizes. overridden

    Suspicious Azure data transfer by identity

    Medium overridden

    An identity executed multiple Microsoft Graph actions, leading to an uncommon increase in API request sizes. overridden

    Unusual data transfer from multiple Azure tenants

    Low overridden

    An identity executed multiple Microsoft Graph actions, leading to an uncommon increase in API request sizes. overridden

  • Uncommon jsp file write by a Java process Medium

    An uncommon jsp file was written by a Java process.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Persistence (TA0003)
    ATT&CK techniques: Server Software Component: Web Shell (T1505.003)
    Required data: XDR Agent with eXtended Threat Hunting (XTH)
    Attacker's goals: Persistence on the host.
    Investigative actions: Check if the file was added during regular java process actions. Check if the jsp file contains malicious content.
  • Uncommon kernel module load Informational 1 variation

    Loading of a kernel module using the modprobe command.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Defense Evasion (TA0005)
    ATT&CK techniques: Rootkit (T1014)
    Required data: XDR Agent
    Detector tags: Kubernetes - AGENT, Containers
    Attacker's goals: Gain persistence using the kernel module.
    Investigative actions: Verify that this isn't IT activity. Look for other hosts executing similar commands.

    Variations

    Uncommon kernel module load in a Kubernetes pod

    Informational overridden

    Loading of a kernel module using the modprobe command. overridden

  • Uncommon local scheduled task creation via schtasks.exe Informational 4 variations

    The schtasks.exe command enables creating, deleting, querying, changing, running, and ending scheduled tasks on a local or remote computer. Adversaries may attempt to use the command to gain persistence on this host using scheduled tasks.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Persistence (TA0003)
    ATT&CK techniques: Scheduled Task/Job (T1053)
    Required data: XDR Agent
    Detector tags: Scheduled tasks Analytics
    Attacker's goals: Attackers may attempt to use the command to gain persistence on the endpoint using scheduled tasks.
    Investigative actions: Review the process that creates the schedule task. Investigate the specific scheduled task execution chain.

    Variations

    Uncommon local scheduled task creation via schtasks.exe by a remote actor

    Informational overridden

    The schtasks.exe command enables creating, deleting, querying, changing, running, and ending scheduled tasks on a local or remote computer. Adversaries may attempt to use the command to gain persistence on this host using scheduled tasks. overridden

    Uncommon scheduled task created by an unsigned and rare actor via schtasks.exe

    Low overridden

    The schtasks.exe command enables creating, deleting, querying, changing, running, and ending scheduled tasks on a local or remote computer. Adversaries may attempt to use the command to gain persistence on this host using scheduled tasks. overridden

    Uncommon scheduled task created by an unsigned actor via schtasks.exe

    Low overridden

    The schtasks.exe command enables creating, deleting, querying, changing, running, and ending scheduled tasks on a local or remote computer. Adversaries may attempt to use the command to gain persistence on this host using scheduled tasks. overridden

    Uncommon scheduled task created by a signed actor from a rare vendor via schtasks.exe

    Low overridden

    The schtasks.exe command enables creating, deleting, querying, changing, running, and ending scheduled tasks on a local or remote computer. Adversaries may attempt to use the command to gain persistence on this host using scheduled tasks. overridden

  • Uncommon login item persistency was registered or modified Informational 4 variations

    An uncommon login item persistence mechanism was registered/modified on the system.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Persistence (TA0003)
    ATT&CK techniques: Boot or Logon Autostart Execution (T1547) Boot or Logon Autostart Execution: Login Items (T1547.015)
    Required data: XDR Agent
    Detector tags: Generic Persistence Analytics
    Attacker's goals: Establish persistent access to the compromised host by registering malicious code.
    Investigative actions: Analyze the persistency item and determine whether it performs any malicious or suspicious actions. Analyze the registered process and determine whether it performs any malicious or suspicious actions. Check the events generated by the process for potential malicious behavior.

    Variations

    Uncommon login item persistency was registered or modified by a security testing tool

    High overridden

    An uncommon login item persistence mechanism was registered/modified on the system by a security testing tool. overridden

    Uncommon login item persistency was registered or modified while using osascript

    Low overridden

    An uncommon login item persistence mechanism was registered/modified on the system while using osascript for persistency registration or as a persistency triggered execution. overridden

    Uncommon login item persistency was registered or modified by an invalidly signed actor process

    Low overridden

    An uncommon login item persistence mechanism was registered/modified on the system by an invalidly signed actor process. overridden

    Uncommon login item persistency was registered or modified by an invalidly signed causality process

    Low overridden

    An uncommon login item persistence mechanism was registered/modified on the system by an invalidly signed causality process. overridden

  • Uncommon macOS process communication to a rare external host Informational 13 variations

    An uncommon process is connecting to an external host that is rarely accessed within the organization. This connection pattern is consistent with malicious activity such as command and control execution, malware download and so on.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Command and Control (TA0011)
    ATT&CK techniques: Application Layer Protocol (T1071)
    Required data: XDR Agent
    Detector tags: Abnormal Communication Analytics
    Attacker's goals: Establish a remote backdoor to issue instructions, deploy additional payloads, and maintain long-term persistence across the infected fleet.
    Investigative actions: Identify the process contacting the remote host and determine whether the traffic is malicious. Look for other endpoints on your network that are also contacting the suspicious host. Inspect the host or URL for suspicious indicators or its presence in malicious reputation lists.

    Variations

    Uncommon macOS process communication to a rare external host by security testing tool

    High overridden

    An uncommon process is connecting to an external host that is rarely accessed within the organization. This connection pattern is consistent with malicious activity such as command and control execution, malware download and so on. overridden

    Uncommon macOS process communication to a rare external host with a frequently abused TLD

    Medium overridden

    An uncommon process is connecting to an external host that is rarely accessed within the organization. This connection pattern is consistent with malicious activity such as command and control execution, malware download and so on. overridden

    Uncommon macOS process communication to a rare external host while using a CLI utility to establish a connection with a messaging service API

    Medium overridden

    An uncommon process is connecting to an external host that is rarely accessed within the organization. This connection pattern is consistent with malicious activity such as command and control execution, malware download and so on. overridden

    Uncommon macOS process communication to a rare external host involving a code sharing website by a high-risk actor

    Medium overridden

    An uncommon process is connecting to an external host that is rarely accessed within the organization. This connection pattern is consistent with malicious activity such as command and control execution, malware download and so on. overridden

    Uncommon macOS process communication to a rare external host involving a code sharing website

    Low overridden

    An uncommon process is connecting to an external host that is rarely accessed within the organization. This connection pattern is consistent with malicious activity such as command and control execution, malware download and so on. overridden

    Uncommon macOS process communication to a rare external host related to LOTTunnels

    Low overridden

    An uncommon process is connecting to an external host that is rarely accessed within the organization. This connection pattern is consistent with malicious activity such as command and control execution, malware download and so on. overridden

    Uncommon macOS process communication to a rare external host with a rare TLD

    Low overridden

    An uncommon process is connecting to an external host that is rarely accessed within the organization. This connection pattern is consistent with malicious activity such as command and control execution, malware download and so on. overridden

    Uncommon macOS process communication to a rare external host while using a CLI utility and piping to script

    Low overridden

    An uncommon process is connecting to an external host that is rarely accessed within the organization. This connection pattern is consistent with malicious activity such as command and control execution, malware download and so on. overridden

    Uncommon macOS process communication to a rare external host while using a CLI utility to download and change permission

    Low overridden

    An uncommon process is connecting to an external host that is rarely accessed within the organization. This connection pattern is consistent with malicious activity such as command and control execution, malware download and so on. overridden

    Uncommon macOS process communication to a rare external host while using a CLI utility running by an unsigned process

    Low overridden

    An uncommon process is connecting to an external host that is rarely accessed within the organization. This connection pattern is consistent with malicious activity such as command and control execution, malware download and so on. overridden

    Uncommon macOS process communication to a rare external host while using a CLI utility and saving data to a temporary folder

    Low overridden

    An uncommon process is connecting to an external host that is rarely accessed within the organization. This connection pattern is consistent with malicious activity such as command and control execution, malware download and so on. overridden

    Uncommon macOS process communication to a rare external host while using a CLI utility and downloading a script

    Low overridden

    An uncommon process is connecting to an external host that is rarely accessed within the organization. This connection pattern is consistent with malicious activity such as command and control execution, malware download and so on. overridden

    Uncommon macOS process communication to a rare external host while using a CLI utility

    Low overridden

    An uncommon process is connecting to an external host that is rarely accessed within the organization. This connection pattern is consistent with malicious activity such as command and control execution, malware download and so on. overridden

  • Uncommon macOS shell command execution Informational 10 variations

    An unusual process execution of a shell command on macOS. This action may indicate possible exploitation or shell command execution via a backdoor.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Execution (TA0002)
    ATT&CK techniques: Command and Scripting Interpreter: Unix Shell (T1059.004) Command and Scripting Interpreter (T1059)
    Required data: XDR Agent
    Detector tags: Shell Analytics
    Attacker's goals: An attacker may attempt to execute a malicious shell command on the system.
    Investigative actions: Check whether the executing process is benign and if this was a desired behavior as part of its normal execution flow. Check the executed shell command (and possible child processes) for malicious actions.

    Variations

    Uncommon macOS shell command execution by a BAS solution

    High overridden

    An unusual process execution of a shell command on macOS. This action may indicate possible exploitation or shell command execution via a backdoor. overridden

    Uncommon macOS shell command execution running a curl / wget in an uncommon way

    High overridden

    An unusual process execution of a shell command on macOS. This action may indicate possible exploitation or shell command execution via a backdoor. overridden

    Uncommon macOS shell command execution taking a screenshot

    Low overridden

    An unusual process execution of a shell command on macOS. This action may indicate possible exploitation or shell command execution via a backdoor. overridden

    Uncommon macOS shell command execution trying to gather information about the system

    Low overridden

    An unusual process execution of a shell command on macOS. This action may indicate possible exploitation or shell command execution via a backdoor. overridden

    Uncommon macOS shell command execution loading a kernel extension

    Low overridden

    An unusual process execution of a shell command on macOS. This action may indicate possible exploitation or shell command execution via a backdoor. overridden

    Uncommon macOS shell command execution, possibly granting file execution permissions

    Low overridden

    An unusual process execution of a shell command on macOS. This action may indicate possible exploitation or shell command execution via a backdoor. overridden

    Uncommon macOS shell command execution running a process kill command

    Low overridden

    An unusual process execution of a shell command on macOS. This action may indicate possible exploitation or shell command execution via a backdoor. overridden

    Uncommon macOS shell command execution executed an AppleScript

    Low overridden

    An unusual process execution of a shell command on macOS. This action may indicate possible exploitation or shell command execution via a backdoor. overridden

    Uncommon macOS shell command execution from an unsigned process

    Low overridden

    An unusual process execution of a shell command on macOS. This action may indicate possible exploitation or shell command execution via a backdoor. overridden

    Uncommon macOS shell command execution of an exceedingly rare process

    Low overridden

    An unusual process execution of a shell command on macOS. This action may indicate possible exploitation or shell command execution via a backdoor. overridden

  • Uncommon msiexec execution of an arbitrary file from a remote location Low 1 variation

    Msiexec is the command-line utility for the Windows Installer. Adversaries may abuse msiexec.exe to proxy execution of malicious payloads from remote locations.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Defense Evasion (TA0005)
    ATT&CK techniques: System Binary Proxy Execution: Msiexec (T1218.007)
    Required data: XDR Agent
    Detector tags: LOLBIN Execution Analytics
    Attacker's goals: Evading security controls and executing arbitrary files from the web.
    Investigative actions: Monitor the command-line arguments of msiexec.exe, For example, the command line msiexec /i http://some_domain.com/www/executable.msi can be legitimate or malicious. Check if the the URL that is encoded in the command line is trusted. Determine if the executed DLL or MSI file is known as legitimate. Confirm whether the initiating process is legitimate and if the user running it knows of its use. Note - the MSI executable can run from other LAN locations, the alert will raise on the WAN connection.

    Variations

    Suspicious msiexec execution on an internet-facing endpoint

    Low overridden

    Suspicious msiexec execution of an arbitrary file from the web on an internet-facing server. overridden

  • Uncommon net group command execution Informational 7 variations

    Uncommon net group command execution which may be used for groups and users enumeration and unauthorized user creation.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Discovery (TA0007) Persistence (TA0003)
    ATT&CK techniques: Permission Groups Discovery (T1069) Create Account (T1136)
    Required data: XDR Agent
    Attacker's goals: Attackers may attempt to use the command to find domain-level group permissions settings or modify domain-level memberships.
    Investigative actions: Check if the queried group is a sensitive one (e.g. administrators). Check whether the initiating process has executed additional discovery commands.

    Variations

    Uncommon unsigned net group administrators command execution

    High overridden

    Uncommon net group command execution which may be used for groups and users enumeration and unauthorized user creation. overridden

    Uncommon unsigned net group administrators command execution - fixed localization issues

    High overridden

    Uncommon net group command execution which may be used for groups and users enumeration and unauthorized user creation. overridden

    Uncommon remote net group administrators command execution

    Low overridden

    Uncommon net group command execution which may be used for groups and users enumeration and unauthorized user creation. overridden

    Uncommon net group administrators command execution

    Medium overridden

    Uncommon net group command execution which may be used for groups and users enumeration and unauthorized user creation. overridden

    Uncommon net group execution

    Low overridden

    Uncommon net group command execution which may be used for groups and users enumeration and unauthorized user creation. overridden

    Uncommon remote net group execution

    Low overridden

    Uncommon net group command execution which may be used for groups and users enumeration and unauthorized user creation. overridden

    Uncommon administrator net group execution by scripting engine or command prompt

    Medium overridden

    Uncommon net group command execution which may be used for groups and users enumeration and unauthorized user creation. overridden

  • Uncommon net localgroup command execution Informational 8 variations

    Uncommon net localgroup command execution which may be used for group and user enumeration and unauthorized user creation.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Discovery (TA0007) Persistence (TA0003)
    ATT&CK techniques: Permission Groups Discovery (T1069) Create Account (T1136)
    Required data: XDR Agent
    Attacker's goals: Attackers may attempt to use the command to find local groups permissions settings or modify local memberships.
    Investigative actions: Check if the queried group is a sensitive one (e.g. administrators). Check whether the initiating process has executed additional discovery commands.

    Variations

    Uncommon net localgroup command execution by an RMM CGO

    Low overridden

    Uncommon net localgroup command execution which may be used for group and user enumeration and unauthorized user creation. The CGO of this process was a Remote Monitoring & Management tool. overridden

    Uncommon net localgroup administrators command execution by a web server process or CGO

    Medium overridden

    Uncommon net localgroup command execution which may be used for group and user enumeration and unauthorized user creation. When executed from a web server, it might be executed from an installed Webshell. overridden

    Uncommon unsigned net localgroup administrators command execution

    Medium overridden

    Uncommon net localgroup command execution which may be used for group and user enumeration and unauthorized user creation. overridden

    Uncommon unsigned net localgroup administrators command execution - fixed localization issues

    Medium overridden

    Uncommon net localgroup command execution which may be used for group and user enumeration and unauthorized user creation. overridden

    Uncommon net localgroup administrators command execution

    Low overridden

    Uncommon net localgroup command execution which may be used for group and user enumeration and unauthorized user creation. overridden

    Uncommon net localgroup execution

    Low overridden

    Uncommon net localgroup command execution which may be used for group and user enumeration and unauthorized user creation. overridden

    Uncommon remote net localgroup execution

    Medium overridden

    Uncommon net localgroup command execution which may be used for group and user enumeration and unauthorized user creation. overridden

    Uncommon administrator net localgroup execution by scripting engine or command prompt

    Low overridden

    Uncommon net localgroup command execution which may be used for group and user enumeration and unauthorized user creation. overridden

  • Uncommon network tunnel creation Informational 3 variations

    An uncommon network tunnel was established.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    12 Hours
    ATT&CK tactics: Command and Control (TA0011)
    ATT&CK techniques: Protocol Tunneling (T1572)
    Required data: Palo Alto Networks Url Logs
    Attacker's goals: Attackers may use SSH or any similar utility to create a network tunnel to allow an attacker to covertly connect to an internal host.
    Investigative actions: Review the external IP/domain using known intelligence tools. Investigate the causality of the process and its user ID to find uncommon behaviors. Search for processes or files that were created by this SSH instance.

    Variations

    Uncommon network tunnel creation

    Informational overridden

    An uncommon network tunnel was established using ACS_ssh.exe. overridden

    Uncommon SSH tunnel to unpopular IP address

    Low overridden

    An uncommon SSH tunnel was established to an unpopular remote IP address at the organization. overridden

    An uncommon network tunnel was established over the default SSH port

    Low overridden

    An unpopular process and command line created a network tunnel over the default SSH port. overridden

  • Uncommon recurring rare external host access Informational 6 variations

    A process has established recurring connections to an uncommon external host.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    14 Days
    ATT&CK tactics: Command and Control (TA0011) Exfiltration (TA0010)
    ATT&CK techniques: Application Layer Protocol (T1071) Exfiltration Over C2 Channel (T1041) Remote Access Tools (T1219)
    Required data: XDR Agent
    Detector tags: Abnormal Communication Analytics
    Attacker's goals: Communicate with malware running on your network to control malware activities, perform software updates on the malware, or to take inventory of infected machines. Additionally, establish command and control channels for remote malware control, conduct discovery activities to gather information about the target environment, or exfiltrate sensitive data from compromised systems.
    Investigative actions: Identify the process contacting the remote host and determine whether the traffic is malicious. Look for other endpoints on your network that are also periodically contacting the same external host. Inspect the domain or URL for malicious indicators or its presence in threat intelligence feeds and reputation lists.

    Variations

    Uncommon recurring rare external host access by an automated penetration testing tool

    High overridden

    A process has established recurring connections to an uncommon external host. overridden

    Uncommon recurring rare external host access to a dynamic DNS domain

    Low overridden

    A process has established recurring connections to an uncommon external host. overridden

    Uncommon recurring rare external host access initiated by a cron job

    Low overridden

    A process has established recurring connections to an uncommon external host. overridden

    Uncommon recurring rare external host access with a rare top-level domain

    Low overridden

    A process has established recurring connections to an uncommon external host. overridden

    Uncommon recurring rare external host access using an exfiltration tool

    Low overridden

    A process has established recurring connections to an uncommon external host. overridden

    Uncommon recurring rare external host access with a sensitive file in actor or causality command line

    Low overridden

    A process has established recurring connections to an uncommon external host. overridden

  • Uncommon remote monitoring and management tool Low 4 variations

    An uncommon Remote Monitoring and Management (RMM) product was observed.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Command and Control (TA0011)
    ATT&CK techniques: Remote Access Tools (T1219)
    Required data: XDR Agent
    Attacker's goals: Accessing a remote machine with full interactive graphic interface capabilities.
    Investigative actions: Check if the product usage is approved. Ask the owners of the machine if they knowingly used this software. Investigate why the software was being used. Check if it was executed remotely or locally.

    Variations

    Uncommon renamed remote monitoring and management tool

    Medium overridden

    An uncommon renamed Remote Monitoring and Management (RMM) product was observed. overridden

    Uncommon remote monitoring and management tool (browser origin)

    Informational overridden

    An uncommon Remote Monitoring and Management (RMM) product was observed. (browser origin). overridden

    Uncommon remote monitoring and management tool extracted from an internet-downloaded archive and executed

    Low overridden

    An uncommon Remote Monitoring and Management (RMM) product extracted from an internet-downloaded archive and executed. overridden

    Uncommon remote monitoring and management tool downloaded from an uncommon source and executed

    Medium overridden

    An uncommon Remote Monitoring and Management (RMM) product downloaded from an uncommon source and executed. overridden

  • Uncommon remote scheduled task creation Low 1 variation

    The schtasks.exe command enables creating, deleting, querying, changing, running, and ending scheduled tasks on a local or remote computer. Adversaries may attempt to use the command to execute programs or persist malware on remote machines.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Execution (TA0002)
    ATT&CK techniques: Scheduled Task/Job (T1053)
    Required data: XDR Agent
    Detector tags: Scheduled tasks Analytics
    Attacker's goals: Attackers can attempt to use the command to execute programs or persist malware on remote endpoints.
    Investigative actions: Investigate the initiator process and whether it should create remote tasks. Investigate the scheduled task execution on the remote machine.

    Variations

    Uncommon remote scheduled task creation by a remote actor via RDP

    High overridden

    The schtasks.exe command enables creating, deleting, querying, changing, running, and ending scheduled tasks on a local or remote computer. Adversaries may attempt to use the command to execute programs or persist malware on remote machines. overridden

  • Uncommon remote service start via sc.exe Low

    The Service Control command (sc.exe) is used to create, start, stop, query, or delete Windows services. Adversaries may attempt to use the command to execute and persist a binary, command, or script.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Execution (TA0002)
    ATT&CK techniques: System Services: Service Execution (T1569.002)
    Required data: XDR Agent
    Detector tags: Malicious Service Analytics
    Attacker's goals: The Service Control command is used to create, start, stop, query, or delete Windows services. Attackers can use the command to attempt to execute and persist a binary, command, or script.
    Investigative actions: Check whether the executed process is benign and if this was desired behavior as part of its normal execution flow. Check the remote host for any evidence of the executed service and investigate it.
  • Uncommon reverse SSH tunnel to external domain/ip Low 3 variations

    An uncommon reverse SSH tunnel might have been created.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Command and Control (TA0011)
    ATT&CK techniques: Protocol Tunneling (T1572)
    Required data: XDR Agent
    Detector tags: Abnormal Communication Analytics
    Attacker's goals: Attackers may use SSH to create an encrypted tunnel to allow an attacker to covertly connect to an internal host.
    Investigative actions: Review the external ip/domain. Investigate the causality of the process.

    Variations

    Uncommon reverse SOCKS proxy SSH tunnel to external domain/ip

    Medium overridden

    An uncommon reverse SSH tunnel might have been created. overridden

    Uncommon reverse SSH tunnel to external domain/ip to a sensitive port via a non-default bind port

    Medium overridden

    An uncommon reverse SSH tunnel might have been created. overridden

    Uncommon reverse SSH tunnel to external domain/ip using a sensitive port

    Low overridden

    An uncommon reverse SSH tunnel might have been created. overridden

  • Uncommon routing table listing via route.exe Low

    The route.exe command is used to display and modify entries in the local IP routing table. Adversaries may attempt to use the command to discover remote systems they could compromise.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Hour
    ATT&CK tactics: Discovery (TA0007)
    ATT&CK techniques: System Network Configuration Discovery (T1016)
    Required data: XDR Agent
    Attacker's goals: Attackers can attempt to use the command to discover remote systems they could compromise.
    Investigative actions: Check whether the command line executed is benign or normal for the host and/or user performing it (e.g. an IT script).
  • Uncommon sensitive filesystem registry hive access Informational 4 variations

    A sensitive registry hive was accessed from the filesystem by an uncommon actor, which is used for credentials dumping.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Credential Access (TA0006)
    ATT&CK techniques: OS Credential Dumping (T1003) OS Credential Dumping: Security Account Manager (T1003.002)
    Required data: XDR Agent with eXtended Threat Hunting (XTH)
    Attacker's goals: Adversary may attempt to extract credentials from the Windows Registry Credentials can then be used to perform lateral movement and access restricted information.
    Investigative actions: Investigate the process that tried to access the registry hive file. Investigate the actions of the user, for which his credentials were stored in the registry hive file.

    Variations

    Uncommon filesystem registry SAM hive access by a lolbin actor in a shadow copy folder

    High overridden

    A sensitive registry hive was accessed from the filesystem by an uncommon actor, which is used for credentials dumping. overridden

    Uncommon sensitive filesystem registry hive access by a lolbin actor in a shadow copy folder

    Medium overridden

    A sensitive registry hive was accessed from the filesystem by an uncommon actor, which is used for credentials dumping. overridden

    Uncommon sensitive filesystem registry hive access by a rare unsigned actor in a shadow copy folder

    Medium overridden

    A sensitive registry hive was accessed from the filesystem by an uncommon actor, which is used for credentials dumping. overridden

    Uncommon sensitive filesystem registry hive access by a rare unsigned actor

    Low overridden

    A sensitive registry hive was accessed from the filesystem by an uncommon actor, which is used for credentials dumping. overridden

  • Uncommon sensitive registry hive dump Low 4 variations

    A sensitive registry hive was extracted, which is used for accessing credentials.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Credential Access (TA0006)
    ATT&CK techniques: OS Credential Dumping (T1003)
    Required data: XDR Agent with eXtended Threat Hunting (XTH)
    Attacker's goals: Adversary may attempt to extract credentials from the Windows Registry Credentials can then be used to perform lateral movement and access restricted information.
    Investigative actions: Investigate the process that tried to access the registry hive. Investigate the actions of the user for which his credentials were stored in the registry hive.

    Variations

    Uncommon sensitive registry hive dump by unsigned and rare process

    High overridden

    A sensitive registry hive was extracted, which is used for accessing credentials. overridden

    Uncommon sensitive registry hive dump by injected process

    High overridden

    A sensitive registry hive was extracted, which is used for accessing credentials. overridden

    Uncommon sensitive registry hive dump by reg.exe lolbin process which was executed by rare causality process

    High overridden

    A sensitive registry hive was extracted, which is used for accessing credentials. overridden

    Uncommon sensitive registry hive dump by reg.exe lolbin process

    Medium overridden

    A sensitive registry hive was extracted, which is used for accessing credentials. overridden

  • Uncommon service stop operation Informational

    An attempt to stop a service was made using an unusual shell command.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Impact (TA0040)
    ATT&CK techniques: Service Stop (T1489)
    Required data: XDR Agent
    Attacker's goals: Attackers may disable services to disrupt system functionality and weaken security defenses.
    Investigative actions: Check whether the executing process is benign and if this was a desired behavior as part of its normal execution flow.
  • Uncommon signed process execution by scheduled task Informational 3 variations

    An uncommon process was executed by a scheduled task.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Persistence (TA0003)
    ATT&CK techniques: Scheduled Task/Job (T1053)
    Required data: XDR Agent
    Detector tags: Scheduled tasks Analytics
    Attacker's goals: Attackers may attempt to gain persistence, privilege escalation or proxy execution on the endpoint using scheduled tasks.
    Investigative actions: Review the process executed by the schedule task. Investigate the specific scheduled task execution chain. Check if the vendor is known in the organization for creating scheduled tasks to execute his product.

    Variations

    Uncommon Microsoft signed process execution by scheduled task

    Informational overridden

    An uncommon process was executed by a scheduled task. overridden

    Uncommon signed process execution by scheduled task on a sensitive server

    Low overridden

    An uncommon process was executed by a scheduled task. overridden

    Rare signed process execution by scheduled task

    Low overridden

    A rare process was executed by a scheduled task. overridden

  • Uncommon user management via net.exe Informational

    The net.exe command is used to add, delete, and otherwise manage the users on a computer. Adversaries may attempt to use the command to discover or add local and domain user accounts.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Discovery (TA0007) Persistence (TA0003)
    ATT&CK techniques: Account Discovery (T1087) Create Account (T1136)
    Required data: XDR Agent
    Attacker's goals: Attackers may attempt to use the command to discover or add local and domain user accounts. The created accounts are to gain additional access to endpoints within your network.
    Investigative actions: Check whether the command line executed is benign or normal for the host and/or user performing it. Check whether the user from the command line is an administrator or other sensitive account.
  • Unicode RTL Override Character High

    An attacker may use a special right-to-left (RTL) override character to trick users into executing malicious files that look like benign file types.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Defense Evasion (TA0005)
    ATT&CK techniques: Obfuscated Files or Information (T1027)
    Required data: XDR Agent
    Attacker's goals: Trick users into executing malicious files by making their file types seem benign.
    Investigative actions: Investigate the executed process. There is no reason for benign files to contain the Unicode right-to-left override character in their name.
  • Unique client computer model was detected via MS-Update protocol Informational

    A unique client computer model was detected via MS-Update protocol.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    7 Days
    ATT&CK tactics: Initial Access (TA0001)
    ATT&CK techniques: Hardware Additions (T1200)
    Required data: Palo Alto Networks Firewall EAL Logs
    Attacker's goals: The Windows Server Update Services enable machines to discover and download software updates from a dedicated update server while providing the necessary client characteristics to install the suitable client version and build. Characteristics may consist of computer model, BIOS version and architecture. A unique computer model in the network may indicate an unauthorized and unmanaged connection to the internal network.
    Investigative actions: Inspect the legitimacy of the host and its hardware components. Verify that this host is not a newly deployed end-point or virtual machine as part of a legitimate IT activity.
  • Unknown DLL was added to the AD FS Global Assembly Cache path Informational Identity Analytics 1 variation

    A new and unknown DLL was created within the Active Directory Federation Services (AD FS) Global Assembly Cache (GAC). Attackers may manipulate IdentityServer adapters to achieve persistence or execute malicious code within the AD FS environment.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Persistence (TA0003) Privilege Escalation (TA0004)
    ATT&CK techniques: Hijack Execution Flow (T1574)
    Required data: XDR Agent with eXtended Threat Hunting (XTH)
    Detector tags: Active Directory Federation Services Analytics
    Attacker's goals: Attackers may inject malicious code into the AD FS server and manipulate the IdentityServer adapters to gain persistence.
    Investigative actions: Check if the AD FS service was stopped or restarted around the time of modification. Identify the user or process responsible for the file creation. Verify if the DLL is digitally signed by Microsoft. Compare the modification timestamp of this DLL against others in the same directory.

    Variations

    Suspicious DLL was added to the AD FS Global Assembly Cache path

    Low overridden

    A new and unknown DLL was created within the Active Directory Federation Services (AD FS) Global Assembly Cache (GAC). Attackers may manipulate IdentityServer adapters to achieve persistence or execute malicious code within the AD FS environment. overridden

  • Unpopular rsync process execution Informational 1 variation

    An unpopular rsync process was executed on the host.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Defense Evasion (TA0005)
    ATT&CK techniques: Hide Artifacts: Hidden Files and Directories (T1564.001)
    Required data: XDR Agent
    Detector tags: Kubernetes - AGENT, Containers
    Attacker's goals: Attackers may attempt to transfer tools or other files to a compromised host.
    Investigative actions: Verify that this isn't IT activity. Look for other hosts executing similar commands.

    Variations

    Unpopular rsync process execution in a Kubernetes Pod

    Informational overridden

    An unpopular rsync process was executed on the host. overridden

  • Unprivileged process opened a registry hive Low

    An unprivileged process opened a registry hive directly.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Credential Access (TA0006)
    ATT&CK techniques: Unsecured Credentials: Credentials In Files (T1552.001)
    Required data: XDR Agent
    Attacker's goals: An attacker may attempt to gain higher privileges.
    Investigative actions: Check whether the command line executed is benign or normal for the host and/or user performing it. Investigate the endpoint to determine if it's a legitimate process that is supposed to run with privileges.
  • Unrecognized internal address (AAD mismatch) Informational Email

    An email was received from an address using an internal domain, but the sender is not found in Active Directory. This may indicate an impersonation attempt or domain spoofing.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Hour 30 Minutes
    ATT&CK tactics: Initial Access (TA0001)
    ATT&CK techniques: Phishing (T1566)
    Required data: Microsoft 365 Emails
    Detector tags: Employee Impersonation, Spear Phishing
    Attacker's goals: The attacker aims to impersonate an internal user to gain trust, bypass security controls, and potentially extract sensitive information or distribute malicious content through internal-looking emails.
    Investigative actions: Verify if the sender address exists in Active Directory. Check historical email activity from the spoofed address. Review email headers for spoofing indicators (SPF, DKIM, DMARC failures). Identify if recipients engaged with the email (clicked links, downloaded attachments). Correlate with other alerts involving the same sender or domain.
  • Unsigned DLL Hijack into a Microsoft process Informational 7 variations

    An unsigned DLL was loaded into a Microsoft signed process. It is not common for the DLL to be loaded into Microsoft processes, which might indicate an attacker performing DLL Hijacking.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Persistence (TA0003) Privilege Escalation (TA0004) Defense Evasion (TA0005)
    ATT&CK techniques: Hijack Execution Flow: DLL (T1574.001)
    Required data: XDR Agent
    Detector tags: DLL Hijacking Analytics
    Attacker's goals: An attacker is attempting to load an untrusted module into a trusted context to avoid detection, gain persistence or to perform privilege escalation.
    Investigative actions: Investigate the loaded module to verify if it is malicious. Investigate if the loading process and the loaded module reside in legitimate locations.

    Variations

    Unsigned DLL Hijack into a recently created Microsoft process which commonly loads the module as signed

    Medium overridden

    An unsigned DLL was loaded into a Microsoft signed process. It is not common for the DLL to be loaded into Microsoft processes, which might indicate an attacker performing DLL Hijacking. In addition, The Microsoft process which commonly loads the module as signed,had loaded the module as unsigned, which might indicate an attacker targeting a popular module name. overridden

    Rare and unsigned DLL into an injected Microsoft process

    Medium overridden

    An unsigned DLL was loaded into a Microsoft signed process. It is not common for the DLL to be loaded into Microsoft processes, which might indicate an attacker performing DLL Hijacking. overridden

    Unsigned DLL Hijack of a low entropy DLL into a Microsoft process

    Low overridden

    An unsigned DLL was loaded into a Microsoft signed process. It is not common for the DLL to be loaded into Microsoft processes, which might indicate an attacker performing DLL Hijacking. overridden

    Unsigned DLL Hijack of a high entropy DLL into a Microsoft process

    Low overridden

    An unsigned DLL was loaded into a Microsoft signed process. It is not common for the DLL to be loaded into Microsoft processes, which might indicate an attacker performing DLL Hijacking. overridden

    Unsigned DLL Hijack into a Microsoft process - the DLL downloaded from an uncommon source

    Low overridden

    An unsigned DLL was loaded into a Microsoft signed process. It is not common for the DLL to be loaded into Microsoft processes, which might indicate an attacker performing DLL Hijacking. overridden

    Unsigned DLL Hijack into a recently created Microsoft process

    Low overridden

    An unsigned DLL was loaded into a Microsoft signed process. It is not common for the DLL to be loaded into Microsoft processes, which might indicate an attacker performing DLL Hijacking. overridden

    Unsigned DLL Hijack into a Microsoft process which was executed by a scheduled task

    Low overridden

    An unsigned DLL was loaded into a Microsoft signed process. It is not common for the DLL to be loaded into Microsoft processes, which might indicate an attacker performing DLL Hijacking. overridden

  • Unsigned DLL Side-Loading Informational 6 variations

    A signed process loaded an unsigned and rare module from the same folder.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Persistence (TA0003) Privilege Escalation (TA0004) Defense Evasion (TA0005)
    ATT&CK techniques: Hijack Execution Flow: DLL (T1574.001)
    Required data: XDR Agent
    Detector tags: DLL Hijacking Analytics
    Attacker's goals: An attacker is attempting to load an untrusted module into a trusted context to avoid detection, gain persistence or to perform privilege escalation.
    Investigative actions: Investigate the loaded module to verify if it is malicious. Investigate if the loading process and the loaded module reside in legitimate locations.

    Variations

    DLL Side-Loading of module bearing an invalid Microsoft signature

    High overridden

    A signed process loaded an unsigned and rare module from the same folder. overridden

    Unsigned DLL Side-Loading to a signed microsoft process by a rare causality actor

    Medium overridden

    A signed process loaded an unsigned and rare module from the same folder. overridden

    Unsigned DLL Side-Loading to a signed microsoft process

    Low overridden

    A signed process loaded an unsigned and rare module from the same folder. overridden

    Unsigned DLL Side-Loading - DLL downloaded from an uncommon source

    Low overridden

    A signed process loaded an unsigned and rare module from the same folder. overridden

    Unsigned high entropy DLL Side-Loading by untrusted causality actor

    Low overridden

    A signed process loaded an unsigned and rare module from the same folder. overridden

    Unsigned DLL Side-Loading which was executed by a scheduled task

    Low overridden

    A signed process loaded an unsigned and rare module from the same folder. overridden

  • Unsigned and unpopular process performed a DLL injection Low 5 variations

    An unsigned process with low popularity injected a dll into another process.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Defense Evasion (TA0005)
    ATT&CK techniques: Process Injection (T1055)
    Required data: XDR Agent
    Detector tags: Injection Analytics
    Attacker's goals: Attackers may inject DLLs into processes to evade process-based defenses, as well as possibly elevate privileges.
    Investigative actions: Check whether the injecting process is benign and if this was a desired behavior as part of its normal execution flow.

    Variations

    Unsigned and unpopular process performed process hollowing DLL injection

    High overridden

    An unsigned process with low popularity injected a dll into another process. overridden

    Unsigned and unpopular process performed queue APC DLL injection

    High overridden

    An unsigned process with low popularity injected a dll into another process. overridden

    Unsigned and unpopular process performed a DLL injection to a sensitive process

    Medium overridden

    An unsigned process with low popularity injected a dll into another process. overridden

    Unsigned and unpopular process performed a DLL injection to a commonly abused process

    High overridden

    An unsigned process with low popularity injected a dll into another process. overridden

    Unsigned and unpopular process performed a DLL injection to a security vendor signed process

    Medium overridden

    An unsigned process with low popularity injected a dll into another process. overridden

  • Unsigned and unpopular process performed an injection Low 7 variations

    An unsigned process with low popularity injected code to another process.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Defense Evasion (TA0005)
    ATT&CK techniques: Process Injection (T1055)
    Required data: XDR Agent
    Detector tags: Injection Analytics
    Attacker's goals: Attackers may inject code into processes to evade process-based defenses, as well as possibly elevate privileges.
    Investigative actions: Check whether the injecting process is benign and if this was a desired behavior as part of its normal execution flow.

    Variations

    Unsigned and unpopular process performed process hollowing injection

    High overridden

    An unsigned process with low popularity injected code to another process. overridden

    Unsigned and unpopular process performed queue APC injection

    High overridden

    An unsigned process with low popularity injected code to another process. overridden

    Unsigned and unpopular process performed injection into a sensitive process

    Medium overridden

    An unsigned process with low popularity injected code to another process. overridden

    Unsigned and unpopular process performed injection into svchost.exe

    High overridden

    An unsigned process with low popularity injected code to another process. This process attempted to obtain System user permissions. overridden

    Unsigned and unpopular process performed injection into a commonly abused process

    High overridden

    An unsigned process with low popularity injected code to another process. overridden

    Unsigned and unpopular process performed injection into a process signed by a security vendor

    Medium overridden

    An unsigned process with low popularity injected code to another process. overridden

    Unsigned and unpopular process executed by a scheduled task performed an injection

    Low overridden

    An unsigned process with low popularity injected code to another process. overridden

  • Unsigned process creates a scheduled task via file access Low 1 variation

    A scheduled task was created via file access from an unsigned process. This is uncommon and may indicate malicious activity.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Execution (TA0002) Persistence (TA0003)
    ATT&CK techniques: Scheduled Task/Job (T1053)
    Required data: XDR Agent
    Detector tags: Scheduled tasks Analytics
    Attacker's goals: Attackers may attempt to gain persistence on the endpoint using scheduled tasks.
    Investigative actions: Review the process executed by the schedule task. Investigate the specific scheduled task execution chain.

    Variations

    Unsigned process creates a scheduled task via file access on a sensitive server

    Medium overridden

    A scheduled task was created via file access from an unsigned process. This is uncommon and may indicate malicious activity. overridden

  • Unsigned process injecting into a Windows system binary with no command line Medium

    An attacker may be trying to avoid detection by injecting their malicious code into a legitimate Windows system binary.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Defense Evasion (TA0005) Privilege Escalation (TA0004)
    ATT&CK techniques: Process Injection (T1055)
    Required data: XDR Agent
    Detector tags: Injection Analytics
    Attacker's goals: Attackers may inject code into processes to evade process-based defenses, as well as possibly elevate privileges.
    Investigative actions: Check whether the injecting process is benign and if this was a desired behavior as part of its normal execution flow.
  • Untrusted process contacted LLM API Informational 1 variation

    An untrusted process contacted an LLM API.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Resource Development (TA0042)
    ATT&CK techniques: Obtain Capabilities: Artificial Intelligence (T1588.007)
    Required data: XDR Agent
    Attacker's goals: Adversaries may use LLM APIs to create malicious payload dynamically. Each payload will be slightly different making detection more complex.
    Investigative actions: Investigate the process that contacted the LLM API. Check if this LLM API access is legitimate and expected. Analyze the data potentially sent to the LLM service.

    Variations

    Untrusted process contacted a rare LLM API

    Low overridden

    An untrusted process contacted a rare LLM API. overridden

  • Unusual ADConnect database file access Informational 2 variations

    An unusual process accessed the ADConnect database files.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Credential Access (TA0006)
    ATT&CK techniques: Unsecured Credentials (T1552)
    Required data: XDR Agent with eXtended Threat Hunting (XTH)
    Attacker's goals: Attackers can abuse the Azure AD Connect database files to get access to the AD Sync account. The AD Sync account is a highly privileged account that can perform a DCSync and get access to on-premise password hashes.
    Investigative actions: See whether this was a legitimate action. Follow process/user/host activities. Follow unusual actions of the AD Sync user. Check for unusual Azure AD authentications. Check for a possible DCSync.

    Variations

    Suspicious access to ADConnect database file

    Medium overridden

    An unusual process accessed the ADConnect database files with some suspicious characteristics that flagged this access attempt as a suspicious. overridden

    Access to ADConnect database file by an unsigned or unusual process

    Low overridden

    An unusual process accessed the ADConnect database files with some suspicious characteristics that flagged this access attempt as a suspicious access. overridden

  • Unusual ADFS Remote Synchronization network connections from non-ADFS server Low

    Detected an unauthorized configuration sync request to the ADFS Policy Store from a non-ADFS server, step for forging SAML tokens in a Golden SAML attack.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Credential Access (TA0006) Lateral Movement (TA0008)
    ATT&CK techniques: Forge Web Credentials: SAML Tokens (T1606.002) Exploitation of Remote Services (T1210)
    Required data: Palo Alto Networks Firewall EAL Logs XDR Agent
    Detector tags: Active Directory Federation Services Analytics
    Attacker's goals: The attack goal is to forge a valid SAML token to impersonate any user and gain persistent, unauthorized access to cloud resources, effectively bypassing MFA and standard security controls.
    Investigative actions: Correlate this network event with AD FS service account activity. The attacker must use the service account's credentials to authenticate this request. Check for a possible DCSync alerts. Check alerts that related to ADFS server. Check for other correlated alerts on on-premises systems that may be related to the Golden SAML attack. Look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Inspect the source machine for the presence of tools like AADInternals or custom SOAP-based scripts.
  • Unusual AI Knowledge Base Modification Low Cloud 1 variation

    An AI knowledge base was modified by an identity that typically doesn't interact with knowledge bases. MITRE ATLAS Technique: AML.T0070 - RAG Poisoning. OWASP Top 10 LLM Technique: LLM04 - Data and Model Poisoning.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    5 Days
    ATT&CK tactics: Impact (TA0040)
    ATT&CK techniques: Data Manipulation: Stored Data Manipulation (T1565.001)
    Required data: AWS Audit Log Gcp Audit Log
    Detector tags: Cloud AI Infrastructure Analytics
    Attacker's goals: Contaminating knowledge base, so that contextual information will be incorrect, biased or harmful.
    Investigative actions: Check the identity that modified the knowledge base. Check recent additions to the knowledge base.

    Variations

    Suspicious AI Knowledge Base Modification

    Medium overridden

    An AI knowledge base was modified by an identity that typically doesn't interact with knowledge bases, adding a new data source type. overridden

  • Unusual AI RAG Knowledge Base Modification Low Cloud

    AI knowledge base was modified by an identity that typically doesn't interact with knowledge bases. MITRE ATLAS Technique: AML.T0070 - RAG Poisoning. OWASP Top 10 LLM Technique: LLM04 - Data and Model Poisoning.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    5 Days
    ATT&CK tactics: Impact (TA0040)
    ATT&CK techniques: Data Manipulation: Stored Data Manipulation (T1565.001)
    Required data: AWS Audit Log Gcp Audit Log
    Detector tags: Cloud AI Infrastructure Analytics
    Attacker's goals: Contaminating knowledge base, so that contextual information will be incorrect, biased or harmful.
    Investigative actions: Check the identity that modified the knowledge base. Check recent additions to the knowledge base.
  • Unusual AI dataset modification Low Cloud 1 variation

    A cloud identity modified an AI dataset. MITRE ATLAS Techniques: AML.T0059 - Erode Dataset Integrity, AML.T0018.000 - Backdoor ML Model: Poison ML Model. OWASP Top 10 LLM Technique: LLM04 - Data and Model Poisoning.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    5 Days
    ATT&CK tactics: Impact (TA0040)
    ATT&CK techniques: Data Manipulation: Stored Data Manipulation (T1565.001)
    Required data: AWS Audit Log Azure Audit Log Gcp Audit Log
    Detector tags: Cloud AI Infrastructure Analytics
    Attacker's goals: Poison datasets used by ML models.
    Investigative actions: Examine changed datasets and determine which ML models were affected. Investigate any unusual activity originating from the suspected identity.

    Variations

    Unusual AI dataset modification from an internal IP address

    Informational overridden

    A cloud identity modified an AI dataset. MITRE ATLAS Techniques: AML.T0059 - Erode Dataset Integrity, AML.T0018.000 - Backdoor ML Model: Poison ML Model. OWASP Top 10 LLM Technique: LLM04 - Data and Model Poisoning. overridden

  • Unusual AI model invocation Informational Cloud

    A cloud identity invoked an AI model for the first time. MITRE ATLAS Technique: AML.T0050 - Command and Scripting Interpreter.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    5 Days
    ATT&CK tactics: Execution (TA0002)
    ATT&CK techniques: Command and Scripting Interpreter: Cloud API (T1059.009)
    Required data: AWS Audit Log Gcp Audit Log
    Detector tags: Cloud AI Infrastructure Analytics
    Attacker's goals: Gain access to AI models.
    Investigative actions: Examine which AI models were invoked. Investigate any unusual activity originating from the suspected identity.
  • Unusual AWS Bedrock model access request Informational Cloud

    A cloud identity requested access to an AWS Bedrock model. MITRE ATLAS Technique: AML.T0012 - Valid Accounts.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    5 Days
    ATT&CK tactics: Initial Access (TA0001)
    ATT&CK techniques: Valid Accounts: Cloud Accounts (T1078.004)
    Required data: AWS Audit Log
    Detector tags: Cloud AI Infrastructure Analytics
    Attacker's goals: Gain access to cloud AI/ML resources and services.
    Investigative actions: Examine which AWS Bedrock models were affected. Investigate any unusual activity originating from the suspected identity.
  • Unusual AWS CLI/SDK activity Informational Cloud

    A cloud identity invoked an API using AWS CLI/SDK for the first time.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    5 Days
    ATT&CK tactics: Execution (TA0002)
    ATT&CK techniques: Command and Scripting Interpreter: Cloud API (T1059.009)
    Required data: AWS Audit Log
    Attacker's goals: Abuse cloud APIs to execute malicious commands.
    Investigative actions: Investigate any unusual activity originating from the suspected identity.
  • Unusual AWS S3 objects deletion Informational Cloud 2 variations

    An identity deleted multiple S3 bucket objects from the project, considerably more than usual.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    1 Hour
    Deduplication:
    5 Days
    ATT&CK tactics: Impact (TA0040)
    ATT&CK techniques: Inhibit System Recovery (T1490) Data Destruction (T1485)
    Required data: AWS Audit Log
    Attacker's goals: Adversaries may delete data to prevent the recovery of a corrupted system. They may also aim to interrupt availability to resources.
    Investigative actions: Identify the deleted objects and their containing bucket. Investigate the identity that performed the deletion and review recent related activity.

    Variations

    A non administrative identity deleted multiple S3 objects from a project

    Low overridden

    An identity deleted multiple S3 bucket objects from the project, considerably more than usual. overridden

    An identity permanently deleted multiple S3 objects from a project

    Medium overridden

    An identity deleted multiple S3 bucket objects from the project, considerably more than usual. overridden

  • Unusual AWS SageMaker notebook access Informational Cloud

    A cloud identity accessed an AWS SageMaker notebook for the first time. MITRE ATLAS Technique: AML.T0008 - Acquire Infrastructure: AI Development Workspaces.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    5 Days
    ATT&CK tactics: Execution (TA0002)
    ATT&CK techniques: Command and Scripting Interpreter: Cloud API (T1059.009)
    Required data: AWS Audit Log
    Detector tags: Cloud AI Infrastructure Analytics
    Attacker's goals: Gain access to AI/ML resources and services.
    Investigative actions: Examine which AWS SageMaker notebooks were accessed. Investigate any unusual activity originating from the suspected identity.
  • Unusual AWS credentials creation Low

    AWS utility was used to create an access key and a secret key.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Persistence (TA0003)
    ATT&CK techniques: Account Manipulation: Additional Cloud Credentials (T1098.001)
    Required data: XDR Agent
    Attacker's goals: Maintain access to an AWS provider.
    Investigative actions: Check the machine timeline and look for abnormal activity. Investigate what other calls were made to the AWS account.
  • Unusual AWS systems manager activity Informational Cloud

    A cloud identity performed an SSM operation for the first time.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Discovery (TA0007) Lateral Movement (TA0008)
    ATT&CK techniques: Cloud Service Discovery (T1526) Remote Services: Cloud Services (T1021.007)
    Required data: AWS Audit Log
    Detector tags: SSM Remote Management Analytics
    Attacker's goals: Manipulate SSM operations to take control over EC2 instances and strengthen the foothold in the cloud environment of the organization, by running critical operating system commands, manipulating the parameters store, and patch management configuration.
    Investigative actions: Check the identity's role designation in the organization. Verify that the identity did not perform any sensitive SSM operation that it shouldn't.
  • Unusual AWS user added to group Low 1 variation

    AWS user added to AWS group, possibly to elevate privileges and gain more access to resources.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Persistence (TA0003)
    ATT&CK techniques: Account Manipulation (T1098)
    Required data: XDR Agent
    Detector tags: Kubernetes - AGENT, Containers
    Attacker's goals: Gain persistence and elevate privileges.
    Investigative actions: Check if the action was done using an automation service. Check if there are any other suspicious activities originated from the same machine/executing user.

    Variations

    Unusual AWS user added to group from a Kubernetes Pod

    Low overridden

    AWS user added to AWS group, possibly to elevate privileges and gain more access to resources. overridden

  • Unusual Azure AD sync module load Low Identity Threat Module 1 variation

    A process that does not usually load the Azure AD Sync mcrypt.dll loaded the module.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Credential Access (TA0006)
    ATT&CK techniques: OS Credential Dumping (T1003)
    Required data: XDR Agent
    Attacker's goals: Attackers can abuse the Azure AD Connect database files to get access to the AD Sync account. The AD Sync account is a highly privileged account that can perform a DCSync and get access to on-premise password hashes.
    Investigative actions: See whether this was a legitimate action. Follow process/user/host activities. Follow unusual actions of the AD Sync user. Check for unusual Azure AD authentications. Check for a possible DCSync.

    Variations

    Unusual Azure AD sync module load by suspicious process

    Medium overridden

    A suspicious process that does not usually load the Azure AD Sync mcrypt.dll loaded the module. overridden