For the complete documentation index, see llms.txt. This page is also available as Markdown.

AI-determined combination of risky alerts under the same causality

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

12 Hours

Deduplication Period

1 Day

Required Data

Requires one of the following data sources: Palo Alto Networks Platform Alerts OR Third-Party Alerts

Detector Tags

AI Insight Fusion Analytics

ATT&CK Tactic

Execution (TA0002)

ATT&CK Technique

User Execution (T1204), Native API (T1106)

Severity

Informational

Description

Multiple alerts likely to be associated with an incident were identified under the same causality.

Attacker's Goals

Perform multiple activities to achieve the attacker's goals in the target environment.

Investigative actions

  • Investigate the causality of these alerts.

  • Track down other suspicious activity under this causality.

Variations

AI-determined combination of risky alerts under the same causality: new service created via command line, suspicious powershell command line, powershell calling invoke expression argument

Synopsis

Field
Value

ATT&CK Tactic

Execution (TA0002)

ATT&CK Technique

User Execution (T1204), Native API (T1106)

Severity

High

Description

A combination of alerts (new service created via command line, suspicious powershell command line, powershell calling invoke expression argument) detected under the same causality chain.

Attacker's Goals

Perform multiple activities to achieve the attacker's goals in the target environment.

Investigative actions

  • Investigate the causality of these alerts.

  • Track down other suspicious activity under this causality.

AI-determined combination of risky alerts under the same causality: active directory enumeration using built in nltest exe, possible arp reconnaissance, unsigned process running from a temporary directory

Synopsis

Field
Value

ATT&CK Tactic

Execution (TA0002)

ATT&CK Technique

User Execution (T1204), Native API (T1106)

Severity

High

Description

A combination of alerts (active directory enumeration using built in nltest exe, possible arp reconnaissance, unsigned process running from a temporary directory) detected under the same causality chain.

Attacker's Goals

Perform multiple activities to achieve the attacker's goals in the target environment.

Investigative actions

  • Investigate the causality of these alerts.

  • Track down other suspicious activity under this causality.

AI-determined combination of risky alerts under the same causality: powershell running with download in the command line, suspicious powershell command line, powershell calling invoke expression argument

Synopsis

Field
Value

ATT&CK Tactic

Execution (TA0002)

ATT&CK Technique

User Execution (T1204), Native API (T1106)

Severity

High

Description

A combination of alerts (powershell running with download in the command line, suspicious powershell command line, powershell calling invoke expression argument) detected under the same causality chain.

Attacker's Goals

Perform multiple activities to achieve the attacker's goals in the target environment.

Investigative actions

  • Investigate the causality of these alerts.

  • Track down other suspicious activity under this causality.

AI-determined combination of risky alerts under the same causality: RAR archive creation with password protection and unsigned temp process

Synopsis

Field
Value

ATT&CK Tactic

Execution (TA0002)

ATT&CK Technique

User Execution (T1204), Native API (T1106)

Severity

High

Description

Command-line creation of a RAR archive with password protection parameters, combined with an unsigned process running from a temporary directory under the same causality chain.

Attacker's Goals

Perform multiple activities to achieve the attacker's goals in the target environment.

Investigative actions

  • Investigate the causality of these alerts.

  • Track down other suspicious activity under this causality.

AI-determined combination of risky alerts under the same causality: file permission changes with boot config modification and unsigned temp process

Synopsis

Field
Value

ATT&CK Tactic

Execution (TA0002)

ATT&CK Technique

User Execution (T1204), Native API (T1106)

Severity

High

Description

Changing file or folder permissions, modification of Windows boot configuration using bcdedit.exe, and an unsigned process running from a temporary directory under the same causality chain.

Attacker's Goals

Perform multiple activities to achieve the attacker's goals in the target environment.

Investigative actions

  • Investigate the causality of these alerts.

  • Track down other suspicious activity under this causality.

AI-determined combination of risky alerts under the same causality: manipulation of mmc registry configuration, powershell possibly attempting to execute as administrator

Synopsis

Field
Value

ATT&CK Tactic

Execution (TA0002)

ATT&CK Technique

User Execution (T1204), Native API (T1106)

Severity

High

Description

A combination of alerts (manipulation of mmc registry configuration, powershell possibly attempting to execute as administrator) detected under the same causality chain.

Attacker's Goals

Perform multiple activities to achieve the attacker's goals in the target environment.

Investigative actions

  • Investigate the causality of these alerts.

  • Track down other suspicious activity under this causality.

AI-determined combination of risky alerts under the same causality: mshta exe launched with suspicious arguments, unsigned process running from a temporary directory

Synopsis

Field
Value

ATT&CK Tactic

Execution (TA0002)

ATT&CK Technique

User Execution (T1204), Native API (T1106)

Severity

High

Description

A combination of alerts (mshta exe launched with suspicious arguments, unsigned process running from a temporary directory) detected under the same causality chain.

Attacker's Goals

Perform multiple activities to achieve the attacker's goals in the target environment.

Investigative actions

  • Investigate the causality of these alerts.

  • Track down other suspicious activity under this causality.

AI-determined combination of risky alerts under the same causality: AD enumeration with shadow copy access

Synopsis

Field
Value

ATT&CK Tactic

Execution (TA0002)

ATT&CK Technique

User Execution (T1204), Native API (T1106)

Severity

High

Description

Active directory enumeration using nltest.exe combined with WMI access to the shadow copy interface under the same causality chain.

Attacker's Goals

Perform multiple activities to achieve the attacker's goals in the target environment.

Investigative actions

  • Investigate the causality of these alerts.

  • Track down other suspicious activity under this causality.

AI-determined combination of risky alerts under the same causality: AD enumeration with AV/FW products enumeration

Synopsis

Field
Value

ATT&CK Tactic

Execution (TA0002)

ATT&CK Technique

User Execution (T1204), Native API (T1106)

Severity

High

Description

Active directory enumeration using nltest.exe combined with enumeration of installed AV or FW products using WMIC under the same causality chain.

Attacker's Goals

Perform multiple activities to achieve the attacker's goals in the target environment.

Investigative actions

  • Investigate the causality of these alerts.

  • Track down other suspicious activity under this causality.

AI-determined combination of risky alerts under the same causality: AD enumeration with MSBuild execution

Synopsis

Field
Value

ATT&CK Tactic

Execution (TA0002)

ATT&CK Technique

User Execution (T1204), Native API (T1106)

Severity

High

Description

Active directory enumeration using nltest.exe combined with MSBuild execution under the same causality chain.

Attacker's Goals

Perform multiple activities to achieve the attacker's goals in the target environment.

Investigative actions

  • Investigate the causality of these alerts.

  • Track down other suspicious activity under this causality.

AI-determined combination of risky alerts under the same causality: unsigned temp process with WMI shadow copy access

Synopsis

Field
Value

ATT&CK Tactic

Execution (TA0002)

ATT&CK Technique

User Execution (T1204), Native API (T1106)

Severity

High

Description

An unsigned process running from a temporary directory combined with WMI access to the shadow copy interface was detected under the same causality chain.

Attacker's Goals

Perform multiple activities to achieve the attacker's goals in the target environment.

Investigative actions

  • Investigate the causality of these alerts.

  • Track down other suspicious activity under this causality.

AI-determined combination of risky alerts under the same causality: boot config modification with shadow copy access

Synopsis

Field
Value

ATT&CK Tactic

Execution (TA0002)

ATT&CK Technique

User Execution (T1204), Native API (T1106)

Severity

High

Description

Modification of Windows boot configuration using bcdedit.exe combined with WMI access to the shadow copy interface under the same causality chain.

Attacker's Goals

Perform multiple activities to achieve the attacker's goals in the target environment.

Investigative actions

  • Investigate the causality of these alerts.

  • Track down other suspicious activity under this causality.

AI-determined combination of risky alerts under the same causality: ping executed with loopback address, msbuild execution, registration of uncommon net services and or assemblies, unsigned process running from a temporary directory

Synopsis

Field
Value

ATT&CK Tactic

Execution (TA0002)

ATT&CK Technique

User Execution (T1204), Native API (T1106)

Severity

Medium

Description

A combination of alerts (ping executed with loopback address, msbuild execution, registration of uncommon net services and or assemblies, unsigned process running from a temporary directory) detected under the same causality chain.

Attacker's Goals

Perform multiple activities to achieve the attacker's goals in the target environment.

Investigative actions

  • Investigate the causality of these alerts.

  • Track down other suspicious activity under this causality.

AI-determined combination of risky alerts under the same causality: powershell running with download in the command line, powershell calling invoke expression argument, query startup programs using wmic exe

Synopsis

Field
Value

ATT&CK Tactic

Execution (TA0002)

ATT&CK Technique

User Execution (T1204), Native API (T1106)

Severity

Medium

Description

A combination of alerts (powershell running with download in the command line, powershell calling invoke expression argument, query startup programs using wmic exe) detected under the same causality chain.

Attacker's Goals

Perform multiple activities to achieve the attacker's goals in the target environment.

Investigative actions

  • Investigate the causality of these alerts.

  • Track down other suspicious activity under this causality.

AI-determined combination of risky alerts under the same causality: task scheduled by commonly abused host process, powershell running with download in the command line, msbuild execution

Synopsis

Field
Value

ATT&CK Tactic

Execution (TA0002)

ATT&CK Technique

User Execution (T1204), Native API (T1106)

Severity

Medium

Description

A combination of alerts (task scheduled by commonly abused host process, powershell running with download in the command line, msbuild execution) detected under the same causality chain.

Attacker's Goals

Perform multiple activities to achieve the attacker's goals in the target environment.

Investigative actions

  • Investigate the causality of these alerts.

  • Track down other suspicious activity under this causality.

AI-determined combination of risky alerts under the same causality: task scheduled by commonly abused host process, a scripting engine was called to run in command line, new service created via command line

Synopsis

Field
Value

ATT&CK Tactic

Execution (TA0002)

ATT&CK Technique

User Execution (T1204), Native API (T1106)

Severity

Medium

Description

A combination of alerts (task scheduled by commonly abused host process, a scripting engine was called to run in command line, new service created via command line) detected under the same causality chain.

Attacker's Goals

Perform multiple activities to achieve the attacker's goals in the target environment.

Investigative actions

  • Investigate the causality of these alerts.

  • Track down other suspicious activity under this causality.

AI-determined combination of risky alerts under the same causality: commonly abused process executed with obfuscated characters, unsigned process running from a temporary directory, manipulation of Windows defender configuration

Synopsis

Field
Value

ATT&CK Tactic

Execution (TA0002)

ATT&CK Technique

User Execution (T1204), Native API (T1106)

Severity

Medium

Description

A combination of alerts (commonly abused process executed with obfuscated characters, unsigned process running from a temporary directory, manipulation of Windows defender configuration) detected under the same causality chain.

Attacker's Goals

Perform multiple activities to achieve the attacker's goals in the target environment.

Investigative actions

  • Investigate the causality of these alerts.

  • Track down other suspicious activity under this causality.

AI-determined combination of risky alerts under the same causality: uncommon ip configuration listing via ipconfig exe, uncommon arp cache listing via arp exe, new service created via command line

Synopsis

Field
Value

ATT&CK Tactic

Execution (TA0002)

ATT&CK Technique

User Execution (T1204), Native API (T1106)

Severity

Medium

Description

A combination of alerts (uncommon ip configuration listing via ipconfig exe, uncommon arp cache listing via arp exe, new service created via command line) detected under the same causality chain.

Attacker's Goals

Perform multiple activities to achieve the attacker's goals in the target environment.

Investigative actions

  • Investigate the causality of these alerts.

  • Track down other suspicious activity under this causality.

AI-determined combination of risky alerts under the same causality: interface enumeration using netsh, possible arp reconnaissance, new service created via command line

Synopsis

Field
Value

ATT&CK Tactic

Execution (TA0002)

ATT&CK Technique

User Execution (T1204), Native API (T1106)

Severity

Medium

Description

A combination of alerts (interface enumeration using netsh, possible arp reconnaissance, new service created via command line) detected under the same causality chain.

Attacker's Goals

Perform multiple activities to achieve the attacker's goals in the target environment.

Investigative actions

  • Investigate the causality of these alerts.

  • Track down other suspicious activity under this causality.

AI-determined combination of risky alerts under the same causality: task scheduled by commonly abused host process, powershell running with download in the command line, powershell calling invoke expression argument

Synopsis

Field
Value

ATT&CK Tactic

Execution (TA0002)

ATT&CK Technique

User Execution (T1204), Native API (T1106)

Severity

Medium

Description

A combination of alerts (task scheduled by commonly abused host process, powershell running with download in the command line, powershell calling invoke expression argument) detected under the same causality chain.

Attacker's Goals

Perform multiple activities to achieve the attacker's goals in the target environment.

Investigative actions

  • Investigate the causality of these alerts.

  • Track down other suspicious activity under this causality.

AI-determined combination of risky alerts under the same causality: Defender manipulation with new service creation and unsigned temp process

Synopsis

Field
Value

ATT&CK Tactic

Execution (TA0002)

ATT&CK Technique

User Execution (T1204), Native API (T1106)

Severity

Medium

Description

Manipulation of Windows Defender configuration, a new service created via command line, and an unsigned process running from a temporary directory under the same causality chain.

Attacker's Goals

Perform multiple activities to achieve the attacker's goals in the target environment.

Investigative actions

  • Investigate the causality of these alerts.

  • Track down other suspicious activity under this causality.

AI-determined combination of risky alerts under the same causality: PowerShell download with suspicious command line and unsigned temp process

Synopsis

Field
Value

ATT&CK Tactic

Execution (TA0002)

ATT&CK Technique

User Execution (T1204), Native API (T1106)

Severity

Medium

Description

PowerShell running with download in the command line, combined with a suspicious PowerShell command line and an unsigned process running from a temporary directory under the same causality chain.

Attacker's Goals

Perform multiple activities to achieve the attacker's goals in the target environment.

Investigative actions

  • Investigate the causality of these alerts.

  • Track down other suspicious activity under this causality.

AI-determined combination of risky alerts under the same causality: ping loopback with PowerShell admin attempt and unsigned temp process

Synopsis

Field
Value

ATT&CK Tactic

Execution (TA0002)

ATT&CK Technique

User Execution (T1204), Native API (T1106)

Severity

Medium

Description

Ping executed with loopback address, PowerShell possibly attempting to execute as administrator, and an unsigned process running from a temporary directory under the same causality chain.

Attacker's Goals

Perform multiple activities to achieve the attacker's goals in the target environment.

Investigative actions

  • Investigate the causality of these alerts.

  • Track down other suspicious activity under this causality.

AI-determined combination of risky alerts under the same causality: AD enumeration with new service creation and unsigned temp process

Synopsis

Field
Value

ATT&CK Tactic

Execution (TA0002)

ATT&CK Technique

User Execution (T1204), Native API (T1106)

Severity

Medium

Description

Active directory enumeration using nltest.exe, a new service created via command line, and an unsigned process running from a temporary directory under the same causality chain.

Attacker's Goals

Perform multiple activities to achieve the attacker's goals in the target environment.

Investigative actions

  • Investigate the causality of these alerts.

  • Track down other suspicious activity under this causality.

AI-determined combination of risky alerts under the same causality: AD enumeration with PsExec remote execution and unsigned temp process

Synopsis

Field
Value

ATT&CK Tactic

Execution (TA0002)

ATT&CK Technique

User Execution (T1204), Native API (T1106)

Severity

Medium

Description

Active directory enumeration using nltest.exe, PsExec executing a command from a remote host, and an unsigned process running from a temporary directory under the same causality chain.

Attacker's Goals

Perform multiple activities to achieve the attacker's goals in the target environment.

Investigative actions

  • Investigate the causality of these alerts.

  • Track down other suspicious activity under this causality.

AI-determined combination of risky alerts under the same causality: MSBuild execution with boot config modification and unsigned temp process

Synopsis

Field
Value

ATT&CK Tactic

Execution (TA0002)

ATT&CK Technique

User Execution (T1204), Native API (T1106)

Severity

Medium

Description

MSBuild execution, modification of Windows boot configuration using bcdedit.exe, and an unsigned process running from a temporary directory under the same causality chain.

Attacker's Goals

Perform multiple activities to achieve the attacker's goals in the target environment.

Investigative actions

  • Investigate the causality of these alerts.

  • Track down other suspicious activity under this causality.

AI-determined combination of risky alerts under the same causality: modification of Windows boot configuration using bcdedit exe, execution of regsvcs regasm with uncommon paths

Synopsis

Field
Value

ATT&CK Tactic

Execution (TA0002)

ATT&CK Technique

User Execution (T1204), Native API (T1106)

Severity

Medium

Description

A combination of alerts (modification of Windows boot configuration using bcdedit exe, execution of regsvcs regasm with uncommon paths) detected under the same causality chain.

Attacker's Goals

Perform multiple activities to achieve the attacker's goals in the target environment.

Investigative actions

  • Investigate the causality of these alerts.

  • Track down other suspicious activity under this causality.

AI-determined combination of risky alerts under the same causality: rundll32 loads a known abused dll, execution of regsvcs regasm with uncommon paths

Synopsis

Field
Value

ATT&CK Tactic

Execution (TA0002)

ATT&CK Technique

User Execution (T1204), Native API (T1106)

Severity

Medium

Description

A combination of alerts (rundll32 loads a known abused dll, execution of regsvcs regasm with uncommon paths) detected under the same causality chain.

Attacker's Goals

Perform multiple activities to achieve the attacker's goals in the target environment.

Investigative actions

  • Investigate the causality of these alerts.

  • Track down other suspicious activity under this causality.

AI-determined combination of risky alerts under the same causality: changing permissions or ownership of a file or folder, bitsadmin exe used to download data

Synopsis

Field
Value

ATT&CK Tactic

Execution (TA0002)

ATT&CK Technique

User Execution (T1204), Native API (T1106)

Severity

Medium

Description

A combination of alerts (changing permissions or ownership of a file or folder, bitsadmin exe used to download data) detected under the same causality chain.

Attacker's Goals

Perform multiple activities to achieve the attacker's goals in the target environment.

Investigative actions

  • Investigate the causality of these alerts.

  • Track down other suspicious activity under this causality.

AI-determined combination of risky alerts under the same causality: new service created via command line, powershell creates a new service

Synopsis

Field
Value

ATT&CK Tactic

Execution (TA0002)

ATT&CK Technique

User Execution (T1204), Native API (T1106)

Severity

Medium

Description

A combination of alerts (new service created via command line, powershell creates a new service) detected under the same causality chain.

Attacker's Goals

Perform multiple activities to achieve the attacker's goals in the target environment.

Investigative actions

  • Investigate the causality of these alerts.

  • Track down other suspicious activity under this causality.

AI-determined combination of risky alerts under the same causality: a scripting engine was called to run in command line, suspicious powershell command line

Synopsis

Field
Value

ATT&CK Tactic

Execution (TA0002)

ATT&CK Technique

User Execution (T1204), Native API (T1106)

Severity

Medium

Description

A combination of alerts (a scripting engine was called to run in command line, suspicious powershell command line) detected under the same causality chain.

Attacker's Goals

Perform multiple activities to achieve the attacker's goals in the target environment.

Investigative actions

  • Investigate the causality of these alerts.

  • Track down other suspicious activity under this causality.

AI-determined combination of risky alerts under the same causality: modification of Windows boot configuration using bcdedit.exe and msbuild.exe execution

Synopsis

Field
Value

ATT&CK Tactic

Execution (TA0002)

ATT&CK Technique

User Execution (T1204), Native API (T1106)

Severity

Medium

Description

A combination of alerts (modification of Windows boot configuration using bcdedit.exe and msbuild.exe execution) detected under the same causality chain.

Attacker's Goals

Perform multiple activities to achieve the attacker's goals in the target environment.

Investigative actions

  • Investigate the causality of these alerts.

  • Track down other suspicious activity under this causality.

AI-determined combination of risky alerts under the same causality: manipulation of bootexecute registry run key, dumping registry hives with passwords

Synopsis

Field
Value

ATT&CK Tactic

Execution (TA0002)

ATT&CK Technique

User Execution (T1204), Native API (T1106)

Severity

Medium

Description

A combination of alerts (manipulation of bootexecute registry run key, dumping registry hives with passwords) detected under the same causality chain.

Attacker's Goals

Perform multiple activities to achieve the attacker's goals in the target environment.

Investigative actions

  • Investigate the causality of these alerts.

  • Track down other suspicious activity under this causality.

AI-determined combination of risky alerts under the same causality: uncommon local scheduled task creation via schtasks exe, suspicious powershell command line

Synopsis

Field
Value

ATT&CK Tactic

Execution (TA0002)

ATT&CK Technique

User Execution (T1204), Native API (T1106)

Severity

Medium

Description

A combination of alerts (uncommon local scheduled task creation via schtasks exe, suspicious powershell command line) detected under the same causality chain.

Attacker's Goals

Perform multiple activities to achieve the attacker's goals in the target environment.

Investigative actions

  • Investigate the causality of these alerts.

  • Track down other suspicious activity under this causality.

AI-determined combination of risky alerts under the same causality: ping loopback with shadow copy access

Synopsis

Field
Value

ATT&CK Tactic

Execution (TA0002)

ATT&CK Technique

User Execution (T1204), Native API (T1106)

Severity

Medium

Description

Ping with loopback address combined with WMI shadow copy access under the same causality chain.

Attacker's Goals

Perform multiple activities to achieve the attacker's goals in the target environment.

Investigative actions

  • Investigate the causality of these alerts.

  • Track down other suspicious activity under this causality.

AI-determined combination of risky alerts under the same causality: Defender manipulation with shadow copy access

Synopsis

Field
Value

ATT&CK Tactic

Execution (TA0002)

ATT&CK Technique

User Execution (T1204), Native API (T1106)

Severity

Medium

Description

Manipulation of Windows Defender configuration combined with WMI access to the shadow copy interface under the same causality chain.

Attacker's Goals

Perform multiple activities to achieve the attacker's goals in the target environment.

Investigative actions

  • Investigate the causality of these alerts.

  • Track down other suspicious activity under this causality.

AI-determined combination of risky alerts under the same causality: AD enumeration with Windows Defender manipulation

Synopsis

Field
Value

ATT&CK Tactic

Execution (TA0002)

ATT&CK Technique

User Execution (T1204), Native API (T1106)

Severity

Medium

Description

Active directory enumeration using nltest.exe combined with manipulation of Windows Defender configuration under the same causality chain.

Attacker's Goals

Perform multiple activities to achieve the attacker's goals in the target environment.

Investigative actions

  • Investigate the causality of these alerts.

  • Track down other suspicious activity under this causality.

AI-determined combination of risky alerts under the same causality: new service creation with shadow copy access

Synopsis

Field
Value

ATT&CK Tactic

Execution (TA0002)

ATT&CK Technique

User Execution (T1204), Native API (T1106)

Severity

Medium

Description

A new service created via command line combined with WMI access to the shadow copy interface under the same causality chain.

Attacker's Goals

Perform multiple activities to achieve the attacker's goals in the target environment.

Investigative actions

  • Investigate the causality of these alerts.

  • Track down other suspicious activity under this causality.

AI-determined combination of risky alerts under the same causality: PowerShell download with shadow copy access

Synopsis

Field
Value

ATT&CK Tactic

Execution (TA0002)

ATT&CK Technique

User Execution (T1204), Native API (T1106)

Severity

Medium

Description

PowerShell running with download in the command line combined with WMI access to the shadow copy interface under the same causality chain.

Attacker's Goals

Perform multiple activities to achieve the attacker's goals in the target environment.

Investigative actions

  • Investigate the causality of these alerts.

  • Track down other suspicious activity under this causality.

AI-determined combination of risky alerts under the same causality: BootExecute manipulation with shadow copy access

Synopsis

Field
Value

ATT&CK Tactic

Execution (TA0002)

ATT&CK Technique

User Execution (T1204), Native API (T1106)

Severity

Medium

Description

Manipulation of the BootExecute Registry run key combined with WMI access to the shadow copy interface under the same causality chain.

Attacker's Goals

Perform multiple activities to achieve the attacker's goals in the target environment.

Investigative actions

  • Investigate the causality of these alerts.

  • Track down other suspicious activity under this causality.

AI-determined combination of risky alerts under the same causality: task scheduled by commonly abused host process, commonly abused process executed with obfuscated characters, powershell running with download in the command line, suspicious powershell command line

Synopsis

Field
Value

ATT&CK Tactic

Execution (TA0002)

ATT&CK Technique

User Execution (T1204), Native API (T1106)

Severity

Low

Description

A combination of alerts (task scheduled by commonly abused host process, commonly abused process executed with obfuscated characters, powershell running with download in the command line, suspicious powershell command line) detected under the same causality chain.

Attacker's Goals

Perform multiple activities to achieve the attacker's goals in the target environment.

Investigative actions

  • Investigate the causality of these alerts.

  • Track down other suspicious activity under this causality.

AI-determined combination of risky alerts under the same causality: powershell script executed from a temporary directory, possible arp reconnaissance, unsigned process running from a temporary directory

Synopsis

Field
Value

ATT&CK Tactic

Execution (TA0002)

ATT&CK Technique

User Execution (T1204), Native API (T1106)

Severity

Low

Description

A combination of alerts (powershell script executed from a temporary directory, possible arp reconnaissance, unsigned process running from a temporary directory) detected under the same causality chain.

Attacker's Goals

Perform multiple activities to achieve the attacker's goals in the target environment.

Investigative actions

  • Investigate the causality of these alerts.

  • Track down other suspicious activity under this causality.

AI-determined combination of risky alerts under the same causality: active directory enumeration using built in nltest exe, suspicious setspn exe execution

Synopsis

Field
Value

ATT&CK Tactic

Execution (TA0002)

ATT&CK Technique

User Execution (T1204), Native API (T1106)

Severity

Low

Description

A combination of alerts (active directory enumeration using built in nltest exe, suspicious setspn exe execution) detected under the same causality chain.

Attacker's Goals

Perform multiple activities to achieve the attacker's goals in the target environment.

Investigative actions

  • Investigate the causality of these alerts.

  • Track down other suspicious activity under this causality.

AI-determined combination of risky alerts under the same causality: suspicious powershell command line, unsigned process running from a temporary directory

Synopsis

Field
Value

ATT&CK Tactic

Execution (TA0002)

ATT&CK Technique

User Execution (T1204), Native API (T1106)

Severity

Low

Description

A combination of alerts (suspicious powershell command line, unsigned process running from a temporary directory) detected under the same causality chain.

Attacker's Goals

Perform multiple activities to achieve the attacker's goals in the target environment.

Investigative actions

  • Investigate the causality of these alerts.

  • Track down other suspicious activity under this causality.

AI-determined combination of risky alerts under the same causality: active directory enumeration using built in nltest exe, powershell running with download in the command line

Synopsis

Field
Value

ATT&CK Tactic

Execution (TA0002)

ATT&CK Technique

User Execution (T1204), Native API (T1106)

Severity

Low

Description

A combination of alerts (active directory enumeration using built in nltest exe, powershell running with download in the command line) detected under the same causality chain.

Attacker's Goals

Perform multiple activities to achieve the attacker's goals in the target environment.

Investigative actions

  • Investigate the causality of these alerts.

  • Track down other suspicious activity under this causality.

AI-determined combination of risky alerts under the same causality: suspicious powershell command line, powershell calling invoke expression argument

Synopsis

Field
Value

ATT&CK Tactic

Execution (TA0002)

ATT&CK Technique

User Execution (T1204), Native API (T1106)

Severity

Low

Description

A combination of alerts (suspicious powershell command line, powershell calling invoke expression argument) detected under the same causality chain.

Attacker's Goals

Perform multiple activities to achieve the attacker's goals in the target environment.

Investigative actions

  • Investigate the causality of these alerts.

  • Track down other suspicious activity under this causality.

Was this helpful?