AI-determined combination of risky alerts under the same causality
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
12 Hours
Deduplication Period
1 Day
Required Data
Requires one of the following data sources: Palo Alto Networks Platform Alerts OR Third-Party Alerts
Detector Tags
AI Insight Fusion Analytics
ATT&CK Tactic
Execution (TA0002)
ATT&CK Technique
User Execution (T1204), Native API (T1106)
Severity
Informational
Description
Multiple alerts likely to be associated with an incident were identified under the same causality.
Attacker's Goals
Perform multiple activities to achieve the attacker's goals in the target environment.
Investigative actions
Investigate the causality of these alerts.
Track down other suspicious activity under this causality.
Variations
AI-determined combination of risky alerts under the same causality: new service created via command line, suspicious powershell command line, powershell calling invoke expression argument
Synopsis
ATT&CK Tactic
Execution (TA0002)
ATT&CK Technique
User Execution (T1204), Native API (T1106)
Severity
High
Description
A combination of alerts (new service created via command line, suspicious powershell command line, powershell calling invoke expression argument) detected under the same causality chain.
Attacker's Goals
Perform multiple activities to achieve the attacker's goals in the target environment.
Investigative actions
Investigate the causality of these alerts.
Track down other suspicious activity under this causality.
AI-determined combination of risky alerts under the same causality: active directory enumeration using built in nltest exe, possible arp reconnaissance, unsigned process running from a temporary directory
Synopsis
ATT&CK Tactic
Execution (TA0002)
ATT&CK Technique
User Execution (T1204), Native API (T1106)
Severity
High
Description
A combination of alerts (active directory enumeration using built in nltest exe, possible arp reconnaissance, unsigned process running from a temporary directory) detected under the same causality chain.
Attacker's Goals
Perform multiple activities to achieve the attacker's goals in the target environment.
Investigative actions
Investigate the causality of these alerts.
Track down other suspicious activity under this causality.
AI-determined combination of risky alerts under the same causality: powershell running with download in the command line, suspicious powershell command line, powershell calling invoke expression argument
Synopsis
ATT&CK Tactic
Execution (TA0002)
ATT&CK Technique
User Execution (T1204), Native API (T1106)
Severity
High
Description
A combination of alerts (powershell running with download in the command line, suspicious powershell command line, powershell calling invoke expression argument) detected under the same causality chain.
Attacker's Goals
Perform multiple activities to achieve the attacker's goals in the target environment.
Investigative actions
Investigate the causality of these alerts.
Track down other suspicious activity under this causality.
AI-determined combination of risky alerts under the same causality: RAR archive creation with password protection and unsigned temp process
Synopsis
ATT&CK Tactic
Execution (TA0002)
ATT&CK Technique
User Execution (T1204), Native API (T1106)
Severity
High
Description
Command-line creation of a RAR archive with password protection parameters, combined with an unsigned process running from a temporary directory under the same causality chain.
Attacker's Goals
Perform multiple activities to achieve the attacker's goals in the target environment.
Investigative actions
Investigate the causality of these alerts.
Track down other suspicious activity under this causality.
AI-determined combination of risky alerts under the same causality: file permission changes with boot config modification and unsigned temp process
Synopsis
ATT&CK Tactic
Execution (TA0002)
ATT&CK Technique
User Execution (T1204), Native API (T1106)
Severity
High
Description
Changing file or folder permissions, modification of Windows boot configuration using bcdedit.exe, and an unsigned process running from a temporary directory under the same causality chain.
Attacker's Goals
Perform multiple activities to achieve the attacker's goals in the target environment.
Investigative actions
Investigate the causality of these alerts.
Track down other suspicious activity under this causality.
AI-determined combination of risky alerts under the same causality: manipulation of mmc registry configuration, powershell possibly attempting to execute as administrator
Synopsis
ATT&CK Tactic
Execution (TA0002)
ATT&CK Technique
User Execution (T1204), Native API (T1106)
Severity
High
Description
A combination of alerts (manipulation of mmc registry configuration, powershell possibly attempting to execute as administrator) detected under the same causality chain.
Attacker's Goals
Perform multiple activities to achieve the attacker's goals in the target environment.
Investigative actions
Investigate the causality of these alerts.
Track down other suspicious activity under this causality.
AI-determined combination of risky alerts under the same causality: mshta exe launched with suspicious arguments, unsigned process running from a temporary directory
Synopsis
ATT&CK Tactic
Execution (TA0002)
ATT&CK Technique
User Execution (T1204), Native API (T1106)
Severity
High
Description
A combination of alerts (mshta exe launched with suspicious arguments, unsigned process running from a temporary directory) detected under the same causality chain.
Attacker's Goals
Perform multiple activities to achieve the attacker's goals in the target environment.
Investigative actions
Investigate the causality of these alerts.
Track down other suspicious activity under this causality.
AI-determined combination of risky alerts under the same causality: AD enumeration with shadow copy access
Synopsis
ATT&CK Tactic
Execution (TA0002)
ATT&CK Technique
User Execution (T1204), Native API (T1106)
Severity
High
Description
Active directory enumeration using nltest.exe combined with WMI access to the shadow copy interface under the same causality chain.
Attacker's Goals
Perform multiple activities to achieve the attacker's goals in the target environment.
Investigative actions
Investigate the causality of these alerts.
Track down other suspicious activity under this causality.
AI-determined combination of risky alerts under the same causality: AD enumeration with AV/FW products enumeration
Synopsis
ATT&CK Tactic
Execution (TA0002)
ATT&CK Technique
User Execution (T1204), Native API (T1106)
Severity
High
Description
Active directory enumeration using nltest.exe combined with enumeration of installed AV or FW products using WMIC under the same causality chain.
Attacker's Goals
Perform multiple activities to achieve the attacker's goals in the target environment.
Investigative actions
Investigate the causality of these alerts.
Track down other suspicious activity under this causality.
AI-determined combination of risky alerts under the same causality: AD enumeration with MSBuild execution
Synopsis
ATT&CK Tactic
Execution (TA0002)
ATT&CK Technique
User Execution (T1204), Native API (T1106)
Severity
High
Description
Active directory enumeration using nltest.exe combined with MSBuild execution under the same causality chain.
Attacker's Goals
Perform multiple activities to achieve the attacker's goals in the target environment.
Investigative actions
Investigate the causality of these alerts.
Track down other suspicious activity under this causality.
AI-determined combination of risky alerts under the same causality: unsigned temp process with WMI shadow copy access
Synopsis
ATT&CK Tactic
Execution (TA0002)
ATT&CK Technique
User Execution (T1204), Native API (T1106)
Severity
High
Description
An unsigned process running from a temporary directory combined with WMI access to the shadow copy interface was detected under the same causality chain.
Attacker's Goals
Perform multiple activities to achieve the attacker's goals in the target environment.
Investigative actions
Investigate the causality of these alerts.
Track down other suspicious activity under this causality.
AI-determined combination of risky alerts under the same causality: boot config modification with shadow copy access
Synopsis
ATT&CK Tactic
Execution (TA0002)
ATT&CK Technique
User Execution (T1204), Native API (T1106)
Severity
High
Description
Modification of Windows boot configuration using bcdedit.exe combined with WMI access to the shadow copy interface under the same causality chain.
Attacker's Goals
Perform multiple activities to achieve the attacker's goals in the target environment.
Investigative actions
Investigate the causality of these alerts.
Track down other suspicious activity under this causality.
AI-determined combination of risky alerts under the same causality: ping executed with loopback address, msbuild execution, registration of uncommon net services and or assemblies, unsigned process running from a temporary directory
Synopsis
ATT&CK Tactic
Execution (TA0002)
ATT&CK Technique
User Execution (T1204), Native API (T1106)
Severity
Medium
Description
A combination of alerts (ping executed with loopback address, msbuild execution, registration of uncommon net services and or assemblies, unsigned process running from a temporary directory) detected under the same causality chain.
Attacker's Goals
Perform multiple activities to achieve the attacker's goals in the target environment.
Investigative actions
Investigate the causality of these alerts.
Track down other suspicious activity under this causality.
AI-determined combination of risky alerts under the same causality: powershell running with download in the command line, powershell calling invoke expression argument, query startup programs using wmic exe
Synopsis
ATT&CK Tactic
Execution (TA0002)
ATT&CK Technique
User Execution (T1204), Native API (T1106)
Severity
Medium
Description
A combination of alerts (powershell running with download in the command line, powershell calling invoke expression argument, query startup programs using wmic exe) detected under the same causality chain.
Attacker's Goals
Perform multiple activities to achieve the attacker's goals in the target environment.
Investigative actions
Investigate the causality of these alerts.
Track down other suspicious activity under this causality.
AI-determined combination of risky alerts under the same causality: task scheduled by commonly abused host process, powershell running with download in the command line, msbuild execution
Synopsis
ATT&CK Tactic
Execution (TA0002)
ATT&CK Technique
User Execution (T1204), Native API (T1106)
Severity
Medium
Description
A combination of alerts (task scheduled by commonly abused host process, powershell running with download in the command line, msbuild execution) detected under the same causality chain.
Attacker's Goals
Perform multiple activities to achieve the attacker's goals in the target environment.
Investigative actions
Investigate the causality of these alerts.
Track down other suspicious activity under this causality.
AI-determined combination of risky alerts under the same causality: task scheduled by commonly abused host process, a scripting engine was called to run in command line, new service created via command line
Synopsis
ATT&CK Tactic
Execution (TA0002)
ATT&CK Technique
User Execution (T1204), Native API (T1106)
Severity
Medium
Description
A combination of alerts (task scheduled by commonly abused host process, a scripting engine was called to run in command line, new service created via command line) detected under the same causality chain.
Attacker's Goals
Perform multiple activities to achieve the attacker's goals in the target environment.
Investigative actions
Investigate the causality of these alerts.
Track down other suspicious activity under this causality.
AI-determined combination of risky alerts under the same causality: commonly abused process executed with obfuscated characters, unsigned process running from a temporary directory, manipulation of Windows defender configuration
Synopsis
ATT&CK Tactic
Execution (TA0002)
ATT&CK Technique
User Execution (T1204), Native API (T1106)
Severity
Medium
Description
A combination of alerts (commonly abused process executed with obfuscated characters, unsigned process running from a temporary directory, manipulation of Windows defender configuration) detected under the same causality chain.
Attacker's Goals
Perform multiple activities to achieve the attacker's goals in the target environment.
Investigative actions
Investigate the causality of these alerts.
Track down other suspicious activity under this causality.
AI-determined combination of risky alerts under the same causality: uncommon ip configuration listing via ipconfig exe, uncommon arp cache listing via arp exe, new service created via command line
Synopsis
ATT&CK Tactic
Execution (TA0002)
ATT&CK Technique
User Execution (T1204), Native API (T1106)
Severity
Medium
Description
A combination of alerts (uncommon ip configuration listing via ipconfig exe, uncommon arp cache listing via arp exe, new service created via command line) detected under the same causality chain.
Attacker's Goals
Perform multiple activities to achieve the attacker's goals in the target environment.
Investigative actions
Investigate the causality of these alerts.
Track down other suspicious activity under this causality.
AI-determined combination of risky alerts under the same causality: interface enumeration using netsh, possible arp reconnaissance, new service created via command line
Synopsis
ATT&CK Tactic
Execution (TA0002)
ATT&CK Technique
User Execution (T1204), Native API (T1106)
Severity
Medium
Description
A combination of alerts (interface enumeration using netsh, possible arp reconnaissance, new service created via command line) detected under the same causality chain.
Attacker's Goals
Perform multiple activities to achieve the attacker's goals in the target environment.
Investigative actions
Investigate the causality of these alerts.
Track down other suspicious activity under this causality.
AI-determined combination of risky alerts under the same causality: task scheduled by commonly abused host process, powershell running with download in the command line, powershell calling invoke expression argument
Synopsis
ATT&CK Tactic
Execution (TA0002)
ATT&CK Technique
User Execution (T1204), Native API (T1106)
Severity
Medium
Description
A combination of alerts (task scheduled by commonly abused host process, powershell running with download in the command line, powershell calling invoke expression argument) detected under the same causality chain.
Attacker's Goals
Perform multiple activities to achieve the attacker's goals in the target environment.
Investigative actions
Investigate the causality of these alerts.
Track down other suspicious activity under this causality.
AI-determined combination of risky alerts under the same causality: Defender manipulation with new service creation and unsigned temp process
Synopsis
ATT&CK Tactic
Execution (TA0002)
ATT&CK Technique
User Execution (T1204), Native API (T1106)
Severity
Medium
Description
Manipulation of Windows Defender configuration, a new service created via command line, and an unsigned process running from a temporary directory under the same causality chain.
Attacker's Goals
Perform multiple activities to achieve the attacker's goals in the target environment.
Investigative actions
Investigate the causality of these alerts.
Track down other suspicious activity under this causality.
AI-determined combination of risky alerts under the same causality: PowerShell download with suspicious command line and unsigned temp process
Synopsis
ATT&CK Tactic
Execution (TA0002)
ATT&CK Technique
User Execution (T1204), Native API (T1106)
Severity
Medium
Description
PowerShell running with download in the command line, combined with a suspicious PowerShell command line and an unsigned process running from a temporary directory under the same causality chain.
Attacker's Goals
Perform multiple activities to achieve the attacker's goals in the target environment.
Investigative actions
Investigate the causality of these alerts.
Track down other suspicious activity under this causality.
AI-determined combination of risky alerts under the same causality: ping loopback with PowerShell admin attempt and unsigned temp process
Synopsis
ATT&CK Tactic
Execution (TA0002)
ATT&CK Technique
User Execution (T1204), Native API (T1106)
Severity
Medium
Description
Ping executed with loopback address, PowerShell possibly attempting to execute as administrator, and an unsigned process running from a temporary directory under the same causality chain.
Attacker's Goals
Perform multiple activities to achieve the attacker's goals in the target environment.
Investigative actions
Investigate the causality of these alerts.
Track down other suspicious activity under this causality.
AI-determined combination of risky alerts under the same causality: AD enumeration with new service creation and unsigned temp process
Synopsis
ATT&CK Tactic
Execution (TA0002)
ATT&CK Technique
User Execution (T1204), Native API (T1106)
Severity
Medium
Description
Active directory enumeration using nltest.exe, a new service created via command line, and an unsigned process running from a temporary directory under the same causality chain.
Attacker's Goals
Perform multiple activities to achieve the attacker's goals in the target environment.
Investigative actions
Investigate the causality of these alerts.
Track down other suspicious activity under this causality.
AI-determined combination of risky alerts under the same causality: AD enumeration with PsExec remote execution and unsigned temp process
Synopsis
ATT&CK Tactic
Execution (TA0002)
ATT&CK Technique
User Execution (T1204), Native API (T1106)
Severity
Medium
Description
Active directory enumeration using nltest.exe, PsExec executing a command from a remote host, and an unsigned process running from a temporary directory under the same causality chain.
Attacker's Goals
Perform multiple activities to achieve the attacker's goals in the target environment.
Investigative actions
Investigate the causality of these alerts.
Track down other suspicious activity under this causality.
AI-determined combination of risky alerts under the same causality: MSBuild execution with boot config modification and unsigned temp process
Synopsis
ATT&CK Tactic
Execution (TA0002)
ATT&CK Technique
User Execution (T1204), Native API (T1106)
Severity
Medium
Description
MSBuild execution, modification of Windows boot configuration using bcdedit.exe, and an unsigned process running from a temporary directory under the same causality chain.
Attacker's Goals
Perform multiple activities to achieve the attacker's goals in the target environment.
Investigative actions
Investigate the causality of these alerts.
Track down other suspicious activity under this causality.
AI-determined combination of risky alerts under the same causality: modification of Windows boot configuration using bcdedit exe, execution of regsvcs regasm with uncommon paths
Synopsis
ATT&CK Tactic
Execution (TA0002)
ATT&CK Technique
User Execution (T1204), Native API (T1106)
Severity
Medium
Description
A combination of alerts (modification of Windows boot configuration using bcdedit exe, execution of regsvcs regasm with uncommon paths) detected under the same causality chain.
Attacker's Goals
Perform multiple activities to achieve the attacker's goals in the target environment.
Investigative actions
Investigate the causality of these alerts.
Track down other suspicious activity under this causality.
AI-determined combination of risky alerts under the same causality: rundll32 loads a known abused dll, execution of regsvcs regasm with uncommon paths
Synopsis
ATT&CK Tactic
Execution (TA0002)
ATT&CK Technique
User Execution (T1204), Native API (T1106)
Severity
Medium
Description
A combination of alerts (rundll32 loads a known abused dll, execution of regsvcs regasm with uncommon paths) detected under the same causality chain.
Attacker's Goals
Perform multiple activities to achieve the attacker's goals in the target environment.
Investigative actions
Investigate the causality of these alerts.
Track down other suspicious activity under this causality.
AI-determined combination of risky alerts under the same causality: changing permissions or ownership of a file or folder, bitsadmin exe used to download data
Synopsis
ATT&CK Tactic
Execution (TA0002)
ATT&CK Technique
User Execution (T1204), Native API (T1106)
Severity
Medium
Description
A combination of alerts (changing permissions or ownership of a file or folder, bitsadmin exe used to download data) detected under the same causality chain.
Attacker's Goals
Perform multiple activities to achieve the attacker's goals in the target environment.
Investigative actions
Investigate the causality of these alerts.
Track down other suspicious activity under this causality.
AI-determined combination of risky alerts under the same causality: new service created via command line, powershell creates a new service
Synopsis
ATT&CK Tactic
Execution (TA0002)
ATT&CK Technique
User Execution (T1204), Native API (T1106)
Severity
Medium
Description
A combination of alerts (new service created via command line, powershell creates a new service) detected under the same causality chain.
Attacker's Goals
Perform multiple activities to achieve the attacker's goals in the target environment.
Investigative actions
Investigate the causality of these alerts.
Track down other suspicious activity under this causality.
AI-determined combination of risky alerts under the same causality: a scripting engine was called to run in command line, suspicious powershell command line
Synopsis
ATT&CK Tactic
Execution (TA0002)
ATT&CK Technique
User Execution (T1204), Native API (T1106)
Severity
Medium
Description
A combination of alerts (a scripting engine was called to run in command line, suspicious powershell command line) detected under the same causality chain.
Attacker's Goals
Perform multiple activities to achieve the attacker's goals in the target environment.
Investigative actions
Investigate the causality of these alerts.
Track down other suspicious activity under this causality.
AI-determined combination of risky alerts under the same causality: modification of Windows boot configuration using bcdedit.exe and msbuild.exe execution
Synopsis
ATT&CK Tactic
Execution (TA0002)
ATT&CK Technique
User Execution (T1204), Native API (T1106)
Severity
Medium
Description
A combination of alerts (modification of Windows boot configuration using bcdedit.exe and msbuild.exe execution) detected under the same causality chain.
Attacker's Goals
Perform multiple activities to achieve the attacker's goals in the target environment.
Investigative actions
Investigate the causality of these alerts.
Track down other suspicious activity under this causality.
AI-determined combination of risky alerts under the same causality: manipulation of bootexecute registry run key, dumping registry hives with passwords
Synopsis
ATT&CK Tactic
Execution (TA0002)
ATT&CK Technique
User Execution (T1204), Native API (T1106)
Severity
Medium
Description
A combination of alerts (manipulation of bootexecute registry run key, dumping registry hives with passwords) detected under the same causality chain.
Attacker's Goals
Perform multiple activities to achieve the attacker's goals in the target environment.
Investigative actions
Investigate the causality of these alerts.
Track down other suspicious activity under this causality.
AI-determined combination of risky alerts under the same causality: uncommon local scheduled task creation via schtasks exe, suspicious powershell command line
Synopsis
ATT&CK Tactic
Execution (TA0002)
ATT&CK Technique
User Execution (T1204), Native API (T1106)
Severity
Medium
Description
A combination of alerts (uncommon local scheduled task creation via schtasks exe, suspicious powershell command line) detected under the same causality chain.
Attacker's Goals
Perform multiple activities to achieve the attacker's goals in the target environment.
Investigative actions
Investigate the causality of these alerts.
Track down other suspicious activity under this causality.
AI-determined combination of risky alerts under the same causality: ping loopback with shadow copy access
Synopsis
ATT&CK Tactic
Execution (TA0002)
ATT&CK Technique
User Execution (T1204), Native API (T1106)
Severity
Medium
Description
Ping with loopback address combined with WMI shadow copy access under the same causality chain.
Attacker's Goals
Perform multiple activities to achieve the attacker's goals in the target environment.
Investigative actions
Investigate the causality of these alerts.
Track down other suspicious activity under this causality.
AI-determined combination of risky alerts under the same causality: Defender manipulation with shadow copy access
Synopsis
ATT&CK Tactic
Execution (TA0002)
ATT&CK Technique
User Execution (T1204), Native API (T1106)
Severity
Medium
Description
Manipulation of Windows Defender configuration combined with WMI access to the shadow copy interface under the same causality chain.
Attacker's Goals
Perform multiple activities to achieve the attacker's goals in the target environment.
Investigative actions
Investigate the causality of these alerts.
Track down other suspicious activity under this causality.
AI-determined combination of risky alerts under the same causality: AD enumeration with Windows Defender manipulation
Synopsis
ATT&CK Tactic
Execution (TA0002)
ATT&CK Technique
User Execution (T1204), Native API (T1106)
Severity
Medium
Description
Active directory enumeration using nltest.exe combined with manipulation of Windows Defender configuration under the same causality chain.
Attacker's Goals
Perform multiple activities to achieve the attacker's goals in the target environment.
Investigative actions
Investigate the causality of these alerts.
Track down other suspicious activity under this causality.
AI-determined combination of risky alerts under the same causality: new service creation with shadow copy access
Synopsis
ATT&CK Tactic
Execution (TA0002)
ATT&CK Technique
User Execution (T1204), Native API (T1106)
Severity
Medium
Description
A new service created via command line combined with WMI access to the shadow copy interface under the same causality chain.
Attacker's Goals
Perform multiple activities to achieve the attacker's goals in the target environment.
Investigative actions
Investigate the causality of these alerts.
Track down other suspicious activity under this causality.
AI-determined combination of risky alerts under the same causality: PowerShell download with shadow copy access
Synopsis
ATT&CK Tactic
Execution (TA0002)
ATT&CK Technique
User Execution (T1204), Native API (T1106)
Severity
Medium
Description
PowerShell running with download in the command line combined with WMI access to the shadow copy interface under the same causality chain.
Attacker's Goals
Perform multiple activities to achieve the attacker's goals in the target environment.
Investigative actions
Investigate the causality of these alerts.
Track down other suspicious activity under this causality.
AI-determined combination of risky alerts under the same causality: BootExecute manipulation with shadow copy access
Synopsis
ATT&CK Tactic
Execution (TA0002)
ATT&CK Technique
User Execution (T1204), Native API (T1106)
Severity
Medium
Description
Manipulation of the BootExecute Registry run key combined with WMI access to the shadow copy interface under the same causality chain.
Attacker's Goals
Perform multiple activities to achieve the attacker's goals in the target environment.
Investigative actions
Investigate the causality of these alerts.
Track down other suspicious activity under this causality.
AI-determined combination of risky alerts under the same causality: task scheduled by commonly abused host process, commonly abused process executed with obfuscated characters, powershell running with download in the command line, suspicious powershell command line
Synopsis
ATT&CK Tactic
Execution (TA0002)
ATT&CK Technique
User Execution (T1204), Native API (T1106)
Severity
Low
Description
A combination of alerts (task scheduled by commonly abused host process, commonly abused process executed with obfuscated characters, powershell running with download in the command line, suspicious powershell command line) detected under the same causality chain.
Attacker's Goals
Perform multiple activities to achieve the attacker's goals in the target environment.
Investigative actions
Investigate the causality of these alerts.
Track down other suspicious activity under this causality.
AI-determined combination of risky alerts under the same causality: powershell script executed from a temporary directory, possible arp reconnaissance, unsigned process running from a temporary directory
Synopsis
ATT&CK Tactic
Execution (TA0002)
ATT&CK Technique
User Execution (T1204), Native API (T1106)
Severity
Low
Description
A combination of alerts (powershell script executed from a temporary directory, possible arp reconnaissance, unsigned process running from a temporary directory) detected under the same causality chain.
Attacker's Goals
Perform multiple activities to achieve the attacker's goals in the target environment.
Investigative actions
Investigate the causality of these alerts.
Track down other suspicious activity under this causality.
AI-determined combination of risky alerts under the same causality: active directory enumeration using built in nltest exe, suspicious setspn exe execution
Synopsis
ATT&CK Tactic
Execution (TA0002)
ATT&CK Technique
User Execution (T1204), Native API (T1106)
Severity
Low
Description
A combination of alerts (active directory enumeration using built in nltest exe, suspicious setspn exe execution) detected under the same causality chain.
Attacker's Goals
Perform multiple activities to achieve the attacker's goals in the target environment.
Investigative actions
Investigate the causality of these alerts.
Track down other suspicious activity under this causality.
AI-determined combination of risky alerts under the same causality: suspicious powershell command line, unsigned process running from a temporary directory
Synopsis
ATT&CK Tactic
Execution (TA0002)
ATT&CK Technique
User Execution (T1204), Native API (T1106)
Severity
Low
Description
A combination of alerts (suspicious powershell command line, unsigned process running from a temporary directory) detected under the same causality chain.
Attacker's Goals
Perform multiple activities to achieve the attacker's goals in the target environment.
Investigative actions
Investigate the causality of these alerts.
Track down other suspicious activity under this causality.
AI-determined combination of risky alerts under the same causality: active directory enumeration using built in nltest exe, powershell running with download in the command line
Synopsis
ATT&CK Tactic
Execution (TA0002)
ATT&CK Technique
User Execution (T1204), Native API (T1106)
Severity
Low
Description
A combination of alerts (active directory enumeration using built in nltest exe, powershell running with download in the command line) detected under the same causality chain.
Attacker's Goals
Perform multiple activities to achieve the attacker's goals in the target environment.
Investigative actions
Investigate the causality of these alerts.
Track down other suspicious activity under this causality.
AI-determined combination of risky alerts under the same causality: suspicious powershell command line, powershell calling invoke expression argument
Synopsis
ATT&CK Tactic
Execution (TA0002)
ATT&CK Technique
User Execution (T1204), Native API (T1106)
Severity
Low
Description
A combination of alerts (suspicious powershell command line, powershell calling invoke expression argument) detected under the same causality chain.
Attacker's Goals
Perform multiple activities to achieve the attacker's goals in the target environment.
Investigative actions
Investigate the causality of these alerts.
Track down other suspicious activity under this causality.
Was this helpful?
