Analytics Alerts
Browse the Cortex analytics alert reference.
3 alerts match the current filters. tactic: TA0010 ✕ technique: T1041 ✕
Download CSV Show ATT&CK heatmapSuspicious Network Connection Originating from AWS SSM Agent Medium Cloud
A process spawned by the AWS SSM agent connected to an anonymous tunnel or TOR IP outside AWS. This may indicate the SSM agent was abused for command and control or data exfiltration.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Command and Control (TA0011) Exfiltration (TA0010)ATT&CK techniques: Application Layer Protocol (T1071) Exfiltration Over C2 Channel (T1041)Required data: XDR AgentDetector tags: SSM Remote Management AnalyticsAttacker's goals: Abuse the Amazon SSM agent to establish a covert command and control channel or exfiltrate data outside the cloud environment.Investigative actions: Verify the process spawned by SSM agent and validate its legitimacy. Inspect the destination IP and ASN in threat intelligence feeds. Review recent SSM document executions on the affected host.Uncommon AppleScript was executed via the command line to contact an external server Low 2 variations
The AppleScript interpreter executed a script designed to contact an external server.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Execution (TA0002) Exfiltration (TA0010)ATT&CK techniques: Command and Scripting Interpreter: AppleScript (T1059.002) Exfiltration Over C2 Channel (T1041)Required data: XDR AgentDetector tags: AppleScript Analytics, Abnormal Communication AnalyticsAttacker's goals: Exfiltrate collected data, including sensitive documents and credentials, from the compromised system.Investigative actions: Analyze the command line and determine whether it performs any malicious or suspicious actions. Check the events generated by the process or its children for potential malicious behavior. Verify the legitimacy of the persistence mechanism being created or modified.Variations
Uncommon AppleScript was executed via the command line to contact an external server using 'curl' to transfer a .zip file
Medium overridden
The AppleScript interpreter executed a script designed to contact an external server. overridden
Uncommon AppleScript was executed via the command line to contact an external server using 'curl' to upload a file
Low overridden
The AppleScript interpreter executed a script designed to contact an external server. overridden
Uncommon recurring rare external host access Informational 6 variations
A process has established recurring connections to an uncommon external host.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 14 Days
ATT&CK tactics: Command and Control (TA0011) Exfiltration (TA0010)ATT&CK techniques: Application Layer Protocol (T1071) Exfiltration Over C2 Channel (T1041) Remote Access Tools (T1219)Required data: XDR AgentDetector tags: Abnormal Communication AnalyticsAttacker's goals: Communicate with malware running on your network to control malware activities, perform software updates on the malware, or to take inventory of infected machines. Additionally, establish command and control channels for remote malware control, conduct discovery activities to gather information about the target environment, or exfiltrate sensitive data from compromised systems.Investigative actions: Identify the process contacting the remote host and determine whether the traffic is malicious. Look for other endpoints on your network that are also periodically contacting the same external host. Inspect the domain or URL for malicious indicators or its presence in threat intelligence feeds and reputation lists.Variations
Uncommon recurring rare external host access by an automated penetration testing tool
High overridden
A process has established recurring connections to an uncommon external host. overridden
Uncommon recurring rare external host access to a dynamic DNS domain
Low overridden
A process has established recurring connections to an uncommon external host. overridden
Uncommon recurring rare external host access initiated by a cron job
Low overridden
A process has established recurring connections to an uncommon external host. overridden
Uncommon recurring rare external host access with a rare top-level domain
Low overridden
A process has established recurring connections to an uncommon external host. overridden
Uncommon recurring rare external host access using an exfiltration tool
Low overridden
A process has established recurring connections to an uncommon external host. overridden
Uncommon recurring rare external host access with a sensitive file in actor or causality command line
Low overridden
A process has established recurring connections to an uncommon external host. overridden