Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source
  • Azure route table creation or modification Informational Cloud 1 variation

    An Azure route table, or one of its individual routes, was created or modified. Azure route tables control how traffic flows between subnets and virtual networks. Adversaries can tamper with route tables to redirect traffic to attacker-controlled destinations, bypassing security appliances or enabling man-in-the-middle attacks.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Defense Evasion (TA0005) Lateral Movement (TA0008)
    ATT&CK techniques: Modify Cloud Compute Infrastructure (T1578) Network Boundary Bridging (T1599) Remote Services: Cloud Services (T1021.007)
    Required data: Azure Audit Log
    Attacker's goals: Redirect or intercept network traffic, bypass security appliances (firewalls, NVAs), or enable lateral movement between Azure subnets.
    Investigative actions: Verify whether the identity should be making route table changes. Inspect the route's address prefix and next-hop -- a 0.0.0.0/0 route pointing at a Virtual Appliance or an internal IP is a strong tamper indicator. Examine other API calls made by the identity around the same time.

    Variations

    Unusual Azure route table creation or modification

    Low overridden

    An Azure route table, or one of its individual routes, was created or modified. Azure route tables control how traffic flows between subnets and virtual networks. Adversaries can tamper with route tables to redirect traffic to attacker-controlled destinations, bypassing security appliances or enabling man-in-the-middle attacks. overridden

  • Chrome OS Remote Access policy was modified in Google Workspace Informational Identity Threat Module, SaaS Threat Detection 1 variation

    A user modified Chrome OS Remote Access configuration in Google Workspace.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Defense Evasion (TA0005) Lateral Movement (TA0008)
    ATT&CK techniques: Impair Defenses (T1562) Remote Services (T1021)
    Required data: Google Workspace Audit Logs
    Detector tags: Google Workspace
    Attacker's goals: Adversaries may modify remote access settings to maintain persistent access and bypass security controls.
    Investigative actions: Verify if the configuration change was authorized. Investigate the source IP address and account involved for malicious activity. Follow further actions performed by the account and Remote Access connections performed.

    Variations

    Suspicious Chrome OS Remote Access policy was modified in Google Workspace

    Low overridden

    A user modified Chrome OS Remote Access configuration in Google Workspace. This is the first time the user performs this operation in the last 30 days. overridden

  • Suspicious SSH Downgrade Low 2 variations

    The endpoint asked for an ssh downgrade, ssh downgrade may enable attackers to perform attacks such as data decryption, man in the middle, session hijack, replay attack and more.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Lateral Movement (TA0008) Defense Evasion (TA0005)
    ATT&CK techniques: Remote Services (T1021) Impair Defenses: Downgrade Attack (T1562.010)
    Required data: Palo Alto Networks Firewall EAL Logs
    Detector tags: NDR Lateral Movement Analytics
    Attacker's goals: Attackers may attempt to move laterally over the network by exploiting problems in a lower version of SSH.
    Investigative actions: Audit the authentication attempts in the SSH server from the alerted host. If the source host authenticated to the SSH server, it may indicate that the attacker managed to connect to the remote host maliciously.

    Variations

    A Host Performed an SSH Downgrade For The First Time In The Last 30 Days

    Low overridden

    The endpoint asked for an ssh downgrade, ssh downgrade may enable attackers to perform attacks such as data decryption, man in the middle, session hijack, replay attack and more. With a lower version than the source host used in the past. overridden

    A Target Server Performed an SSH Downgrade For The First Time In The Last 30 Days

    Low overridden

    The endpoint asked for an ssh downgrade, ssh downgrade may enable attackers to perform attacks such as data decryption, man in the middle, session hijack, replay attack and more. With a lower version than the remote host used in the past. overridden