Alerts related to data source "XDR Agent".
A browser was opened in private mode
A commonly abused process connected to a rare cloud resource
A commonly abused process connected to a rare external host
A compressed file was exfiltrated over SSH
A compromised process accessed a rare cloud resource
A compromised process accessed a rare external host
A contained executable from a mounted share initiated a suspicious outbound network connection
A contained executable was executed by an unusual process
A disabled user attempted to log in
A LOLBIN was copied to a different location
A Possible crypto miner was detected on a host
A process connected to a rare cloud resource
A process connected to a rare external host
A process connected to rare external host
A process is masquerading as a common Microsoft product
A process was executed with a command line obfuscated by Unicode character substitution
A rare DLL, signed by an uncommon vendor, was hijacked into a Microsoft process
A rare local administrator login
A service was disabled
A Successful login from TOR
A suspicious process enrolled for a certificate
A TCP stream was created directly in a shell
A third-party utility was copied to a different location
A Torrent client was detected on a host
A user accessed an uncommon AppID
A user accessed multiple time-consuming websites
A user authenticated with weak NTLM to multiple hosts
A user logged in from an abnormal country or ASN
A user logged on to multiple workstations via Schannel
Abnormal Communication to a Rare Domain
Abnormal communication with a rare combination of TLS and HTTP User Agent
Abnormal connections to a dormant host from a newly seen endpoint
Abnormal ICMP echo (PING) to multiple hosts
Abnormal network communication through TOR using an uncommon port
Abnormal network communication with a rare combination of HTTP User Agent and HTTP Server
Abnormal process connection to default Meterpreter port
Abnormal RDP connections to multiple hosts
Abnormal RDP connections to multiple hosts from a rarely seen host
Abnormal RDP session to a remote host from a rarely seen host
Abnormal Recurring Communications to a Rare Domain
Abnormal SMB activity to multiple hosts
Abnormal SMB scanning activity to multiple hosts
Abnormal User Login to Domain Controller
Account probing
Adding execution privileges
An internal Cloud resource performed port scan on external networks
An uncommon lolbin execution by scheduled task
An uncommon RDP session from a managed host
An uncommon RDP session was established
An uncommon service was started
An unsigned process created scheduled task and performed an injection
Analytics enhanced NGFW Threat Alert - Rare Internal Firewall Vulnerability Threat Alert
AppleScript executed a shell script
AppleScript interpreter dynamic library loaded into a process
AppleScript process executed with a rare command line
Attempt to execute a command on a remote host using PsExec.exe
Authentication Attempt From a Dormant Account
Autorun.inf created in root C drive
Azure Privilege Escalation Using an Application
Bitsadmin.exe persistence using command-line callback
Brute-force attempt on a local account
Cached credentials discovery with cmdkey
Certutil pfx parsing
Cloud IMDS access followed by remote token usage
Command execution in a Kubernetes pod
Command execution via wmiexec
Command running with COMSPEC in the command line argument
Common third-party software name masquerading
Commonly abused AutoIT script connects to an external domain
Commonly abused process launched as a system service
Compressing data using python
Conhost.exe spawned a suspicious cmd process
Contained process execution with a rare GitHub URL
Copy a process memory file
Copy a user's GnuPG directory with rsync
Delayed Deletion of Files
Discovery of host users via WMIC
DNS Tunneling
Download a script using the python requests module
Download pattern that resembles Peer to Peer traffic
Encoded information using Windows certificate management tool
Executable moved to Windows system folder
Execution of an uncommon process at an early startup stage
Execution of an uncommon process at an early startup stage by Windows system binary
Execution of an uncommon process with a local/domain user SID at an early startup stage
Execution of an uncommon process with a local/domain user SID at early startup by a system binary
Execution of command from within a Kubernetes pod using kubelet credentials
Execution of dllhost.exe with an empty command line
Execution of masqueraded third-party utility
Execution of renamed lolbin
External Login Password Spray
Extracting credentials from Unix files
Failed Connections
Failed DNS
Failed Login For a Long Username With Special Characters
Failed Login For Locked-Out Account
File transfer from unusual IP using known tools
Fodhelper.exe UAC bypass
Globally uncommon high entropy module was loaded
Globally uncommon high entropy process was executed
Globally uncommon image load from a signed process
Globally uncommon injection from a signed process
Globally uncommon IP address by a common process (sha256)
Globally uncommon IP address connection from a signed process
Globally uncommon process execution from a signed process
Globally uncommon root domain from a signed process
Globally uncommon root-domain port combination by a common process (sha256)
Globally uncommon root-domain port combination from a signed process
Hidden Attribute was added to a file using attrib.exe
HTTP with suspicious characteristics
Hydra Password Brute-Force Tool Execution
Increase in Job-Related Site Visits
Indicator blocking
Indirect command execution using the Program Compatibility Assistant
Injection into rundll32.exe
Installation of a new System-V service
Interactive at.exe privilege escalation method
Interactive local account enumeration
Interactive login by a machine account
Interactive login by a service account
Interactive login from a shared user account
Internal Login Password Spray
Iptables configuration command was executed
JS runtime attempted to read Git authentication tokens
Kerberos Pre-Auth Failures by Host
Kerberos Pre-Auth Failures by User and Host
Kerberos Traffic from Non-Standard Process
Kerberos User Enumeration
Keylogging using system commands
Kubelet server communication from a pod
Kubernetes API server communication from within a pod
Kubernetes environment enumeration activity
Kubernetes nsenter container escape
Kubernetes secret enumeration activity
Kubernetes version disclosure
Kubernetes vulnerability scanner activity
Large Upload (FTP)
Large Upload (Generic)
Large Upload (HTTPS)
Large Upload (SMTP)
LDAP traffic from non-standard process
Linux local user account creation
Linux network share discovery
Linux process execution with a rare GitHub URL
Local account discovery
Login attempt by a honey user
Login by a dormant user
LOLBAS executable injects into another process
LOLBIN process executed with a high integrity level
Machine Account NTLM Relay
Manipulation of netsh helper DLLs Registry keys
Masquerading as the Linux crond process
Massive upload to a rare storage or mail domain
Memory dumping with comsvcs.dll
Microsoft Configuration Manager device registration and policy request
Microsoft Office injects code into a process
Microsoft Office Process Spawning a Suspicious One-Liner
Microsoft Office process spawns a commonly abused process
Microsoft Office process spawns conhost.exe
Mimikatz command-line arguments
Modification of PAM
Mount command was executed from within a Kubernetes pod to list all the attached filesystems
MpCmdRun.exe was used to download files into the system
Mshta.exe launched with suspicious arguments
Mshta.exe spawns from a browser process
MSI accessed a web page running a server-side script
Msiexec execution of an executable from an uncommon remote location
Multiple discovery commands
Multiple discovery commands on a Linux host by the same process
Multiple discovery commands on a Windows host by the same process
Multiple discovery-like commands
Multiple Rare LOLBIN Process Executions by User
Multiple Rare Process Executions in Organization
Multiple uncommon SSH Servers with the same Server host key
Multiple user accounts failed login due to account lockouts
Multiple users authenticated with weak NTLM to a host
Multiple Weakly-Encrypted Kerberos Tickets Received
Netcat makes or gets connections
New addition to Windows Defender exclusion list
New Administrative Behavior
New FTP Server
New Shared User Account
NTLM Brute Force
NTLM Brute Force on a Service Account
NTLM Brute Force on an Administrator Account
NTLM Hash Harvesting
NTLM Password Spray
NTLM Relay
Office process spawned with suspicious command-line arguments
Okta FastPass reported phishing attack suspected
Permission Groups discovery commands
Phantom DLL Loading
Ping to localhost from an uncommon, unsigned parent process
Port Sweep
Possible AS-REP Roasting Attack
Possible binary padding using dd
Possible brute force on sudo user
Possible brute force or configuration change attempt on cytool
Possible Brute-Force attempt
Possible code downloading from a remote host by Regsvr32
Possible collection of screen captures with Windows Problem Steps Recorder
Possible compromised machine account
Possible data obfuscation
Possible DLL Hijack into a Microsoft process
Possible DLL Search Order Hijacking
Possible Email collection using Outlook RPC
Possible external RDP Brute-Force
Possible Insider Threat Activity
Possible IPFS traffic was detected
Possible Kerberoasting attack
Possible Kerberoasting without SPNs
Possible Kerberos relay attack
Possible malicious .NET compilation started by a commonly abused process
Possible network service discovery via command-line tool
Possible network sniffing attempt via tcpdump or tshark
Possible new DHCP server
Possible Pass-the-Hash
Possible path traversal via HTTP request
Possible phishing attack via Microsoft Teams
Possible RDP session hijacking using tscon.exe
Possible Search For Password Files
Possible TGT reuse from different hosts (pass the ticket)
Possible use of IPFS was detected
Potential extraction of NAA Account Credentials in Microsoft Configuration Manager
Potential NTLM Relay Attack
Potential NTLM Relay Attack against a Microsoft Configuration Manager Site Server
PowerShell runs suspicious base64-encoded commands
PowerShell suspicious flags
Procdump executed from an atypical directory
PsExec was executed with a suspicious command line
Python HTTP server started
Random-Looking Domain Names
Rare access to known advertising domains
Rare AppID usage to a rare destination
Rare binary connected to a rare cloud resource
Rare binary connected to a rare external host
Rare communication over email ports to external email server by unsigned process
Rare file transfer over SMB protocol
Rare LOLBIN Process Execution by User
Rare MS-Update traffic over HTTP
Rare NTLM Access By User To Host
Rare NTLM Usage by User
Rare process created an SSH session to an uncommon cloud resource
Rare process created an SSH session to an uncommon external host
Rare process executed by an AppleScript
Rare process execution by user
Rare process execution in organization
Rare process spawned by srvany.exe
Rare process with VNC server capabilities started
Rare RDP session to a remote host
Rare security product signed executable executed in the network
Rare signature signed executable executed in the network
Rare SMB session to a remote host
Rare SMTP/S Session
Rare SSH Session
Rare Unix process divided files by size
Rare unsigned process execution by scheduled task
Rare Unsigned Process Spawned by Office Process Under Suspicious Directory
Rare Windows Remote Management (WinRM) HTTP Activity
Rare WinRM Session
RDP Connection to localhost
RDP from an unmanaged endpoint in a typically managed subnet
Reading bash command history file
Recurring access to rare domain
Recurring access to rare IP
Recurring rare domain access from an unsigned process
Recurring rare domain access to dynamic DNS domain
Registration of Uncommon .NET Services and/or Assemblies
Remote account enumeration
Remote code execution into Kubernetes Pod
Remote command execution via wmic.exe
Remote DCOM command execution
Remote PsExec-like command execution
Remote service command execution from an uncommon source
Remote service start from an uncommon source
Remote WMI process execution
Retrieval of kubelet credentials
Run downloaded script using pipe
Rundll32.exe executes a rare unsigned module
Rundll32.exe running with no command-line arguments
Rundll32.exe spawns conhost.exe
Scrcons.exe Rare Child Process
Screensaver process executed from Users or temporary folder
Script file added to startup-related Registry keys
Scripting engine connected to a rare external host
Service execution via sc.exe
Setuid and Setgid file bit manipulation
Signed process creates a scheduled task via file access
Signed process performed an unpopular DLL injection
Signed process performed an unpopular injection
SMB Traffic from Non-Standard Process
Spam Bot Traffic
SSH authentication brute force attempts
Stored credentials exported using credwiz.exe
Subdomain Fuzzing
Sudoedit Brute force attempt
SUID/GUID permission discovery
Suspicious .NET process loads an MSBuild DLL
Suspicious authentication package registered
Suspicious Certutil AD CS contact
Suspicious certutil command line
Suspicious container orchestration job
Suspicious container reconnaissance activity in a Kubernetes pod
Suspicious container runtime connection from within a Kubernetes Pod
Suspicious curl user agent
Suspicious data encryption
Suspicious disablement of the Windows Firewall
Suspicious DNS traffic
Suspicious docker image download from an unusual repository
Suspicious dump of ntds.dit using Shadow Copy with ntdsutil/vssadmin
Suspicious External RDP Login
Suspicious failed HTTP request - potential Spring4Shell exploit
Suspicious HTTP parameters detected
Suspicious ICMP packet
Suspicious ICMP traffic that resembles smurf attack
Suspicious module load using direct syscall
Suspicious Network Connection Originating from AWS SSM Agent
Suspicious NTLM authentication with machine account
Suspicious PowerShell Command Line
Suspicious PowerShell Enumeration of Running Processes
Suspicious print processor registered
Suspicious process accessed a site masquerading as Google
Suspicious process executed with a high integrity level
Suspicious process execution from tmp folder
Suspicious process execution in a privileged container
Suspicious process loads a known PowerShell module
Suspicious Process Spawned by Adobe Reader
Suspicious Process Spawned by wininit.exe
Suspicious proxy environment variable setting
Suspicious RunOnce Parent Process
Suspicious runonce.exe parent process
Suspicious SearchProtocolHost.exe parent process
Suspicious setspn.exe execution
Suspicious SMB connection from domain controller
Suspicious sshpass command execution
Suspicious successful RDP connection to localhost
Suspicious systemd timer activity
Suspicious time provider registered
Suspicious usage of File Server Remote VSS Protocol (FSRVP)
Svchost.exe loads a rare unsigned module
System information discovery via psinfo.exe
System shutdown or reboot
Tampering with Internet Explorer Protected Mode configuration
TGT request with a spoofed sAMAccountName - Network
The CA policy EditFlags was queried
The Linux system firewall was disabled
Uncommon AppleScript containing a potential obfuscation technique was executed
Uncommon AppleScript containing a potential persistence command was executed via the command line
Uncommon AppleScript designed to access credential files was executed via the command line
Uncommon AppleScript designed to access cryptocurrency wallet data was executed via the command line
Uncommon AppleScript designed to access sensitive application data was executed via the command line
Uncommon AppleScript designed to capture screen or clipboard data was executed via the command line
Uncommon AppleScript potentially utilizes credential-grabbing techniques to steal user passwords
Uncommon AppleScript was executed via the command line to contact an external server
Uncommon AppleScript with a potential defense-evasion command was executed via the command line
Uncommon AppleScript with a potential discovery command was executed via the command line
Uncommon ARP cache listing via arp.exe
Uncommon attempt to clear shell history
Uncommon cloud CLI tool usage
Uncommon communication to an instant messaging server
Uncommon DLL-sideloading from a logical CD-ROM (ISO) device
Uncommon DotNet module load relationship
Uncommon driver loaded
Uncommon execution of ODBCConf
Uncommon IP Configuration Listing via ipconfig.exe
Uncommon kernel module load
Uncommon Launch Agent persistency was registered or modified
Uncommon Launch Daemon persistency was registered or modified
Uncommon Linux process communication to a rare external host
Uncommon Linux remote shell command execution
Uncommon Linux shell command execution
Uncommon local scheduled task creation via schtasks.exe
Uncommon login item persistency was registered or modified
Uncommon macOS process communication to a rare external host
Uncommon macOS shell command execution
Uncommon Managed Object Format (MOF) compiler usage
Uncommon msiexec execution of an arbitrary file from a remote location
Uncommon net group command execution
Uncommon net localgroup command execution
Uncommon RDP connection
Uncommon recurring rare external host access
Uncommon remote monitoring and management tool
Uncommon remote scheduled task creation
Uncommon remote service start via sc.exe
Uncommon reverse SSH tunnel to external domain/ip
Uncommon routing table listing via route.exe
Uncommon Service Create/Config
Uncommon service stop operation
Uncommon signed process execution by scheduled task
Uncommon SQL like command line
Uncommon SSH session was established
Uncommon user management via net command
Uncommon VNC server communication
Uncommon WPAD queries
Unicode RTL Override Character
Unpopular rsync process execution
Unprivileged process opened a registry hive
Unsigned and unpopular process performed a DLL injection
Unsigned and unpopular process performed an injection
Unsigned DLL Hijack into a Microsoft process
Unsigned DLL Side-Loading
Unsigned process creates a scheduled task via file access
Unsigned process injecting into a Windows system binary with no command line
Untrusted process contacted LLM API
Unusual ADFS Remote Synchronization network connections from non-ADFS server
Unusual AWS credentials creation
Unusual AWS user added to group
Unusual Azure AD sync module load
Unusual cloud Instance Metadata Service (IMDS) access
Unusual compressed file password protection
Unusual DB process spawning a shell
Unusual internal access to network device management interface
Unusual Kubernetes dashboard communication from a pod
Unusual Lolbins Process Spawned by InstallUtil.exe
Unusual process accessed the PowerShell history file
Unusual process executed by AWS Systems Manager
Unusual Process Spawned by Nginx in Ingress-Nginx pod
Unusual SSH Activity
Unusual SSH activity that resembles SSH proxy
Unusual weak authentication by user
Upload pattern that resembles Peer to Peer traffic
VM Detection attempt on Linux
Wbadmin deleted files in quiet mode
Weakly-Encrypted Kerberos TGT Response
Weakly-Encrypted Kerberos Ticket Requested
Web server CGO executed an uncommon process
WebDAV drive mounted from net.exe over HTTPS
Windows CGO, actor and action processes with anomalous characteristics
Windows CGO, actor process and action module with anomalous characteristics
Windows Event Log was cleared using wevtutil.exe
Windows Installer exploitation for local privilege escalation
Windows LOLBIN executable connected to a rare external host
WmiPrvSe.exe Rare Child Command Line
Wscript/Cscript loads .NET DLLs
Wsmprovhost.exe Rare Child Process
Was this helpful?