Analytics Alerts
Browse the Cortex analytics alert reference.
4 alerts match the current filters. tactic: TA0003 ✕ technique: T1059 ✕
Download CSV Show ATT&CK heatmapAzure VM extension abuse attempt Informational Cloud 1 variation
A suspicious Azure VM extension operation was detected. Attackers can use CustomScriptExtension to execute arbitrary scripts on VMs, VMAccessExtension to reset local passwords for persistence, or delete the IaaSAntimalware extension to disable antimalware protection and evade detection.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Execution (TA0002) Persistence (TA0003) Defense Evasion (TA0005)ATT&CK techniques: Cloud Administration Command (T1651) Command and Scripting Interpreter: Cloud API (T1059.009) Account Manipulation (T1098) Impair Defenses: Disable or Modify Tools (T1562.001)Required data: Azure Audit LogAttacker's goals: Execute arbitrary code on VMs without network access (CustomScriptExtension). Gain persistent access by resetting local admin passwords (VMAccessExtension). Disable antimalware to deploy malware undetected (IaaSAntimalware deletion).Investigative actions: Identify the extension type involved (CustomScriptExtension, VMAccessExtension, IaaSAntimalware). For CustomScriptExtension: review the script payload executed on the VM. For VMAccessExtension: check if local admin credentials were reset and audit subsequent logins. For IaaSAntimalware deletion: verify the virtual machine audit log after the extension was removed. Verify whether the identity performing the operation is authorized to manage VM extensions. Check for correlated suspicious activity such as new role assignments or lateral movement.Variations
Unusual azure VM extension abuse
Low overridden
A suspicious Azure VM extension operation was detected. Attackers can use CustomScriptExtension to execute arbitrary scripts on VMs, VMAccessExtension to reset local passwords for persistence, or delete the IaaSAntimalware extension to disable antimalware protection and evade detection. overridden
Google Workspace automation was created Informational Identity Threat Module, SaaS Threat Detection 1 variation
Google Workspace automation was created.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Execution (TA0002) Persistence (TA0003) Exfiltration (TA0010)ATT&CK techniques: Command and Scripting Interpreter (T1059) Event Triggered Execution (T1546) Automated Exfiltration (T1020)Required data: Google Workspace Audit LogsDetector tags: Google WorkspaceAttacker's goals: Adversaries may create automations to maintain persistence, execute malicious code, or exfiltrate data automatically.Investigative actions: Verify if the automation creation was authorized and expected for this user. Investigate the automation logic to determine if it is malicious. Investigate other suspicious activities performed by the user around the same timeframe.Variations
Google Workspace automation was created for a public document
Low overridden
Google Workspace automation was created. The document that the automation was created for is publicly shared. overridden
Okta API Token Created Informational Identity Threat Module, SaaS Threat Detection 1 variation
A user created a new API token in Okta.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Privilege Escalation (TA0004) Execution (TA0002) Persistence (TA0003)ATT&CK techniques: Access Token Manipulation: Make and Impersonate Token (T1134.003) Command and Scripting Interpreter: Cloud API (T1059.009) Account Manipulation: Additional Cloud Credentials (T1098.001)Required data: Okta Audit LogDetector tags: Okta Audit AnalyticsAttacker's goals: An attacker's goal is to gain unauthorized access, compromise user accounts, and perform malicious actions within an organization's systems, potentially leading to data breaches, account takeovers, and the escalation of privileges.Investigative actions: Review the actions taken by the user that created the token. Follow the operations made using this API token by the ID token. Contact the user who created the API token and ensure that the API token is needed.Variations
An Okta API token was generated with suspicious characteristics
Low overridden
A user created a new API token in Okta with suspicious conditions. overridden
Uncommon AppleScript containing a potential persistence command was executed via the command line Low 2 variations
The AppleScript interpreter executed an uncommon command potentially used for persistence to maintain system access.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Execution (TA0002) Persistence (TA0003)ATT&CK techniques: Command and Scripting Interpreter: AppleScript (T1059.002) Boot or Logon Autostart Execution (T1547)Required data: XDR AgentDetector tags: AppleScript Analytics, Generic Persistence AnalyticsAttacker's goals: Establish persistence on the system through various mechanisms to maintain access.Investigative actions: Analyze the command line and determine whether it performs any malicious or suspicious actions. Check the events generated by the process or its children for potential malicious behavior. Verify the legitimacy of the persistence mechanism being created or modified.Variations
Uncommon AppleScript containing a potential persistence command was executed via the command line targeting a .plist file for modification
High overridden
The AppleScript interpreter executed an uncommon command potentially used for persistence to maintain system access. overridden
Uncommon AppleScript containing a potential persistence command was executed via the command line targeting launchctl load command execution
Low overridden
The AppleScript interpreter executed an uncommon command potentially used for persistence to maintain system access. overridden