Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source
  • Azure VM extension abuse attempt Informational Cloud 1 variation

    A suspicious Azure VM extension operation was detected. Attackers can use CustomScriptExtension to execute arbitrary scripts on VMs, VMAccessExtension to reset local passwords for persistence, or delete the IaaSAntimalware extension to disable antimalware protection and evade detection.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Execution (TA0002) Persistence (TA0003) Defense Evasion (TA0005)
    ATT&CK techniques: Cloud Administration Command (T1651) Command and Scripting Interpreter: Cloud API (T1059.009) Account Manipulation (T1098) Impair Defenses: Disable or Modify Tools (T1562.001)
    Required data: Azure Audit Log
    Attacker's goals: Execute arbitrary code on VMs without network access (CustomScriptExtension). Gain persistent access by resetting local admin passwords (VMAccessExtension). Disable antimalware to deploy malware undetected (IaaSAntimalware deletion).
    Investigative actions: Identify the extension type involved (CustomScriptExtension, VMAccessExtension, IaaSAntimalware). For CustomScriptExtension: review the script payload executed on the VM. For VMAccessExtension: check if local admin credentials were reset and audit subsequent logins. For IaaSAntimalware deletion: verify the virtual machine audit log after the extension was removed. Verify whether the identity performing the operation is authorized to manage VM extensions. Check for correlated suspicious activity such as new role assignments or lateral movement.

    Variations

    Unusual azure VM extension abuse

    Low overridden

    A suspicious Azure VM extension operation was detected. Attackers can use CustomScriptExtension to execute arbitrary scripts on VMs, VMAccessExtension to reset local passwords for persistence, or delete the IaaSAntimalware extension to disable antimalware protection and evade detection. overridden

  • Google Workspace automation was created Informational Identity Threat Module, SaaS Threat Detection 1 variation

    Google Workspace automation was created.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Execution (TA0002) Persistence (TA0003) Exfiltration (TA0010)
    ATT&CK techniques: Command and Scripting Interpreter (T1059) Event Triggered Execution (T1546) Automated Exfiltration (T1020)
    Required data: Google Workspace Audit Logs
    Detector tags: Google Workspace
    Attacker's goals: Adversaries may create automations to maintain persistence, execute malicious code, or exfiltrate data automatically.
    Investigative actions: Verify if the automation creation was authorized and expected for this user. Investigate the automation logic to determine if it is malicious. Investigate other suspicious activities performed by the user around the same timeframe.

    Variations

    Google Workspace automation was created for a public document

    Low overridden

    Google Workspace automation was created. The document that the automation was created for is publicly shared. overridden

  • Okta API Token Created Informational Identity Threat Module, SaaS Threat Detection 1 variation

    A user created a new API token in Okta.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Privilege Escalation (TA0004) Execution (TA0002) Persistence (TA0003)
    ATT&CK techniques: Access Token Manipulation: Make and Impersonate Token (T1134.003) Command and Scripting Interpreter: Cloud API (T1059.009) Account Manipulation: Additional Cloud Credentials (T1098.001)
    Required data: Okta Audit Log
    Detector tags: Okta Audit Analytics
    Attacker's goals: An attacker's goal is to gain unauthorized access, compromise user accounts, and perform malicious actions within an organization's systems, potentially leading to data breaches, account takeovers, and the escalation of privileges.
    Investigative actions: Review the actions taken by the user that created the token. Follow the operations made using this API token by the ID token. Contact the user who created the API token and ensure that the API token is needed.

    Variations

    An Okta API token was generated with suspicious characteristics

    Low overridden

    A user created a new API token in Okta with suspicious conditions. overridden

  • Uncommon AppleScript containing a potential persistence command was executed via the command line Low 2 variations

    The AppleScript interpreter executed an uncommon command potentially used for persistence to maintain system access.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Execution (TA0002) Persistence (TA0003)
    ATT&CK techniques: Command and Scripting Interpreter: AppleScript (T1059.002) Boot or Logon Autostart Execution (T1547)
    Required data: XDR Agent
    Detector tags: AppleScript Analytics, Generic Persistence Analytics
    Attacker's goals: Establish persistence on the system through various mechanisms to maintain access.
    Investigative actions: Analyze the command line and determine whether it performs any malicious or suspicious actions. Check the events generated by the process or its children for potential malicious behavior. Verify the legitimacy of the persistence mechanism being created or modified.

    Variations

    Uncommon AppleScript containing a potential persistence command was executed via the command line targeting a .plist file for modification

    High overridden

    The AppleScript interpreter executed an uncommon command potentially used for persistence to maintain system access. overridden

    Uncommon AppleScript containing a potential persistence command was executed via the command line targeting launchctl load command execution

    Low overridden

    The AppleScript interpreter executed an uncommon command potentially used for persistence to maintain system access. overridden