Analytics Low

Multiple alerts of different MITRE tactics were seen

Multiple alerts of different MITRE tactics were seen on the same host under the same causality.

Module:
Platform Analytics
Data source:
Palo Alto Networks Platform Alerts, Third-Party Alerts
ATT&CK tactics: Execution (TA0002)
ATT&CK techniques: User Execution (T1204) Native API (T1106)
Attacker's goals:

Execute multiple covert actions to circumvent detection.

Investigative actions:

Investigate the causality of all the linked alerts. It is visible in the bottom of the causality page. Assess whether it looks like a threat actor executing multiple tactics.

Test period:
3 Hours
Deduplication:
1 Day