> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/ai-determined-combination-of-risky-alerts-under-the-same-causality.md).

# AI-determined combination of risky alerts under the same causality

### Synopsis

| Field                | Value                                                                                                          |
| -------------------- | -------------------------------------------------------------------------------------------------------------- |
| Activation Period    | 14 Days                                                                                                        |
| Training Period      | 30 Days                                                                                                        |
| Test Period          | 12 Hours                                                                                                       |
| Deduplication Period | 1 Day                                                                                                          |
| Required Data        | <p>Requires one of the following data sources:<br>Palo Alto Networks Platform Alerts OR Third-Party Alerts</p> |
| Detector Tags        | AI Insight Fusion Analytics                                                                                    |
| ATT\&CK Tactic       | Execution (TA0002)                                                                                             |
| ATT\&CK Technique    | User Execution (T1204), Native API (T1106)                                                                     |
| Severity             | Informational                                                                                                  |

### Description

Multiple alerts likely to be associated with an incident were identified under the same causality.

### Attacker's Goals

Perform multiple activities to achieve the attacker's goals in the target environment.

### Investigative actions

* Investigate the causality of these alerts.
* Track down other suspicious activity under this causality.

### Variations

<details>

<summary>AI-determined combination of risky alerts under the same causality: new service created via command line, suspicious powershell command line, powershell calling invoke expression argument</summary>

**Synopsis**

| Field             | Value                                      |
| ----------------- | ------------------------------------------ |
| ATT\&CK Tactic    | Execution (TA0002)                         |
| ATT\&CK Technique | User Execution (T1204), Native API (T1106) |
| Severity          | High                                       |

**Description**

A combination of alerts (new service created via command line, suspicious powershell command line, powershell calling invoke expression argument) detected under the same causality chain.

**Attacker's Goals**

Perform multiple activities to achieve the attacker's goals in the target environment.

**Investigative actions**

* Investigate the causality of these alerts.
* Track down other suspicious activity under this causality.

</details>

<details>

<summary>AI-determined combination of risky alerts under the same causality: active directory enumeration using built in nltest exe, possible arp reconnaissance, unsigned process running from a temporary directory</summary>

**Synopsis**

| Field             | Value                                      |
| ----------------- | ------------------------------------------ |
| ATT\&CK Tactic    | Execution (TA0002)                         |
| ATT\&CK Technique | User Execution (T1204), Native API (T1106) |
| Severity          | High                                       |

**Description**

A combination of alerts (active directory enumeration using built in nltest exe, possible arp reconnaissance, unsigned process running from a temporary directory) detected under the same causality chain.

**Attacker's Goals**

Perform multiple activities to achieve the attacker's goals in the target environment.

**Investigative actions**

* Investigate the causality of these alerts.
* Track down other suspicious activity under this causality.

</details>

<details>

<summary>AI-determined combination of risky alerts under the same causality: powershell running with download in the command line, suspicious powershell command line, powershell calling invoke expression argument</summary>

**Synopsis**

| Field             | Value                                      |
| ----------------- | ------------------------------------------ |
| ATT\&CK Tactic    | Execution (TA0002)                         |
| ATT\&CK Technique | User Execution (T1204), Native API (T1106) |
| Severity          | High                                       |

**Description**

A combination of alerts (powershell running with download in the command line, suspicious powershell command line, powershell calling invoke expression argument) detected under the same causality chain.

**Attacker's Goals**

Perform multiple activities to achieve the attacker's goals in the target environment.

**Investigative actions**

* Investigate the causality of these alerts.
* Track down other suspicious activity under this causality.

</details>

<details>

<summary>AI-determined combination of risky alerts under the same causality: RAR archive creation with password protection and unsigned temp process</summary>

**Synopsis**

| Field             | Value                                      |
| ----------------- | ------------------------------------------ |
| ATT\&CK Tactic    | Execution (TA0002)                         |
| ATT\&CK Technique | User Execution (T1204), Native API (T1106) |
| Severity          | High                                       |

**Description**

Command-line creation of a RAR archive with password protection parameters, combined with an unsigned process running from a temporary directory under the same causality chain.

**Attacker's Goals**

Perform multiple activities to achieve the attacker's goals in the target environment.

**Investigative actions**

* Investigate the causality of these alerts.
* Track down other suspicious activity under this causality.

</details>

<details>

<summary>AI-determined combination of risky alerts under the same causality: file permission changes with boot config modification and unsigned temp process</summary>

**Synopsis**

| Field             | Value                                      |
| ----------------- | ------------------------------------------ |
| ATT\&CK Tactic    | Execution (TA0002)                         |
| ATT\&CK Technique | User Execution (T1204), Native API (T1106) |
| Severity          | High                                       |

**Description**

Changing file or folder permissions, modification of Windows boot configuration using bcdedit.exe, and an unsigned process running from a temporary directory under the same causality chain.

**Attacker's Goals**

Perform multiple activities to achieve the attacker's goals in the target environment.

**Investigative actions**

* Investigate the causality of these alerts.
* Track down other suspicious activity under this causality.

</details>

<details>

<summary>AI-determined combination of risky alerts under the same causality: manipulation of mmc registry configuration, powershell possibly attempting to execute as administrator</summary>

**Synopsis**

| Field             | Value                                      |
| ----------------- | ------------------------------------------ |
| ATT\&CK Tactic    | Execution (TA0002)                         |
| ATT\&CK Technique | User Execution (T1204), Native API (T1106) |
| Severity          | High                                       |

**Description**

A combination of alerts (manipulation of mmc registry configuration, powershell possibly attempting to execute as administrator) detected under the same causality chain.

**Attacker's Goals**

Perform multiple activities to achieve the attacker's goals in the target environment.

**Investigative actions**

* Investigate the causality of these alerts.
* Track down other suspicious activity under this causality.

</details>

<details>

<summary>AI-determined combination of risky alerts under the same causality: mshta exe launched with suspicious arguments, unsigned process running from a temporary directory</summary>

**Synopsis**

| Field             | Value                                      |
| ----------------- | ------------------------------------------ |
| ATT\&CK Tactic    | Execution (TA0002)                         |
| ATT\&CK Technique | User Execution (T1204), Native API (T1106) |
| Severity          | High                                       |

**Description**

A combination of alerts (mshta exe launched with suspicious arguments, unsigned process running from a temporary directory) detected under the same causality chain.

**Attacker's Goals**

Perform multiple activities to achieve the attacker's goals in the target environment.

**Investigative actions**

* Investigate the causality of these alerts.
* Track down other suspicious activity under this causality.

</details>

<details>

<summary>AI-determined combination of risky alerts under the same causality: AD enumeration with shadow copy access</summary>

**Synopsis**

| Field             | Value                                      |
| ----------------- | ------------------------------------------ |
| ATT\&CK Tactic    | Execution (TA0002)                         |
| ATT\&CK Technique | User Execution (T1204), Native API (T1106) |
| Severity          | High                                       |

**Description**

Active directory enumeration using nltest.exe combined with WMI access to the shadow copy interface under the same causality chain.

**Attacker's Goals**

Perform multiple activities to achieve the attacker's goals in the target environment.

**Investigative actions**

* Investigate the causality of these alerts.
* Track down other suspicious activity under this causality.

</details>

<details>

<summary>AI-determined combination of risky alerts under the same causality: AD enumeration with AV/FW products enumeration</summary>

**Synopsis**

| Field             | Value                                      |
| ----------------- | ------------------------------------------ |
| ATT\&CK Tactic    | Execution (TA0002)                         |
| ATT\&CK Technique | User Execution (T1204), Native API (T1106) |
| Severity          | High                                       |

**Description**

Active directory enumeration using nltest.exe combined with enumeration of installed AV or FW products using WMIC under the same causality chain.

**Attacker's Goals**

Perform multiple activities to achieve the attacker's goals in the target environment.

**Investigative actions**

* Investigate the causality of these alerts.
* Track down other suspicious activity under this causality.

</details>

<details>

<summary>AI-determined combination of risky alerts under the same causality: AD enumeration with MSBuild execution</summary>

**Synopsis**

| Field             | Value                                      |
| ----------------- | ------------------------------------------ |
| ATT\&CK Tactic    | Execution (TA0002)                         |
| ATT\&CK Technique | User Execution (T1204), Native API (T1106) |
| Severity          | High                                       |

**Description**

Active directory enumeration using nltest.exe combined with MSBuild execution under the same causality chain.

**Attacker's Goals**

Perform multiple activities to achieve the attacker's goals in the target environment.

**Investigative actions**

* Investigate the causality of these alerts.
* Track down other suspicious activity under this causality.

</details>

<details>

<summary>AI-determined combination of risky alerts under the same causality: unsigned temp process with WMI shadow copy access</summary>

**Synopsis**

| Field             | Value                                      |
| ----------------- | ------------------------------------------ |
| ATT\&CK Tactic    | Execution (TA0002)                         |
| ATT\&CK Technique | User Execution (T1204), Native API (T1106) |
| Severity          | High                                       |

**Description**

An unsigned process running from a temporary directory combined with WMI access to the shadow copy interface was detected under the same causality chain.

**Attacker's Goals**

Perform multiple activities to achieve the attacker's goals in the target environment.

**Investigative actions**

* Investigate the causality of these alerts.
* Track down other suspicious activity under this causality.

</details>

<details>

<summary>AI-determined combination of risky alerts under the same causality: boot config modification with shadow copy access</summary>

**Synopsis**

| Field             | Value                                      |
| ----------------- | ------------------------------------------ |
| ATT\&CK Tactic    | Execution (TA0002)                         |
| ATT\&CK Technique | User Execution (T1204), Native API (T1106) |
| Severity          | High                                       |

**Description**

Modification of Windows boot configuration using bcdedit.exe combined with WMI access to the shadow copy interface under the same causality chain.

**Attacker's Goals**

Perform multiple activities to achieve the attacker's goals in the target environment.

**Investigative actions**

* Investigate the causality of these alerts.
* Track down other suspicious activity under this causality.

</details>

<details>

<summary>AI-determined combination of risky alerts under the same causality: ping executed with loopback address, msbuild execution, registration of uncommon net services and or assemblies, unsigned process running from a temporary directory</summary>

**Synopsis**

| Field             | Value                                      |
| ----------------- | ------------------------------------------ |
| ATT\&CK Tactic    | Execution (TA0002)                         |
| ATT\&CK Technique | User Execution (T1204), Native API (T1106) |
| Severity          | Medium                                     |

**Description**

A combination of alerts (ping executed with loopback address, msbuild execution, registration of uncommon net services and or assemblies, unsigned process running from a temporary directory) detected under the same causality chain.

**Attacker's Goals**

Perform multiple activities to achieve the attacker's goals in the target environment.

**Investigative actions**

* Investigate the causality of these alerts.
* Track down other suspicious activity under this causality.

</details>

<details>

<summary>AI-determined combination of risky alerts under the same causality: powershell running with download in the command line, powershell calling invoke expression argument, query startup programs using wmic exe</summary>

**Synopsis**

| Field             | Value                                      |
| ----------------- | ------------------------------------------ |
| ATT\&CK Tactic    | Execution (TA0002)                         |
| ATT\&CK Technique | User Execution (T1204), Native API (T1106) |
| Severity          | Medium                                     |

**Description**

A combination of alerts (powershell running with download in the command line, powershell calling invoke expression argument, query startup programs using wmic exe) detected under the same causality chain.

**Attacker's Goals**

Perform multiple activities to achieve the attacker's goals in the target environment.

**Investigative actions**

* Investigate the causality of these alerts.
* Track down other suspicious activity under this causality.

</details>

<details>

<summary>AI-determined combination of risky alerts under the same causality: task scheduled by commonly abused host process, powershell running with download in the command line, msbuild execution</summary>

**Synopsis**

| Field             | Value                                      |
| ----------------- | ------------------------------------------ |
| ATT\&CK Tactic    | Execution (TA0002)                         |
| ATT\&CK Technique | User Execution (T1204), Native API (T1106) |
| Severity          | Medium                                     |

**Description**

A combination of alerts (task scheduled by commonly abused host process, powershell running with download in the command line, msbuild execution) detected under the same causality chain.

**Attacker's Goals**

Perform multiple activities to achieve the attacker's goals in the target environment.

**Investigative actions**

* Investigate the causality of these alerts.
* Track down other suspicious activity under this causality.

</details>

<details>

<summary>AI-determined combination of risky alerts under the same causality: task scheduled by commonly abused host process, a scripting engine was called to run in command line, new service created via command line</summary>

**Synopsis**

| Field             | Value                                      |
| ----------------- | ------------------------------------------ |
| ATT\&CK Tactic    | Execution (TA0002)                         |
| ATT\&CK Technique | User Execution (T1204), Native API (T1106) |
| Severity          | Medium                                     |

**Description**

A combination of alerts (task scheduled by commonly abused host process, a scripting engine was called to run in command line, new service created via command line) detected under the same causality chain.

**Attacker's Goals**

Perform multiple activities to achieve the attacker's goals in the target environment.

**Investigative actions**

* Investigate the causality of these alerts.
* Track down other suspicious activity under this causality.

</details>

<details>

<summary>AI-determined combination of risky alerts under the same causality: commonly abused process executed with obfuscated characters, unsigned process running from a temporary directory, manipulation of Windows defender configuration</summary>

**Synopsis**

| Field             | Value                                      |
| ----------------- | ------------------------------------------ |
| ATT\&CK Tactic    | Execution (TA0002)                         |
| ATT\&CK Technique | User Execution (T1204), Native API (T1106) |
| Severity          | Medium                                     |

**Description**

A combination of alerts (commonly abused process executed with obfuscated characters, unsigned process running from a temporary directory, manipulation of Windows defender configuration) detected under the same causality chain.

**Attacker's Goals**

Perform multiple activities to achieve the attacker's goals in the target environment.

**Investigative actions**

* Investigate the causality of these alerts.
* Track down other suspicious activity under this causality.

</details>

<details>

<summary>AI-determined combination of risky alerts under the same causality: uncommon ip configuration listing via ipconfig exe, uncommon arp cache listing via arp exe, new service created via command line</summary>

**Synopsis**

| Field             | Value                                      |
| ----------------- | ------------------------------------------ |
| ATT\&CK Tactic    | Execution (TA0002)                         |
| ATT\&CK Technique | User Execution (T1204), Native API (T1106) |
| Severity          | Medium                                     |

**Description**

A combination of alerts (uncommon ip configuration listing via ipconfig exe, uncommon arp cache listing via arp exe, new service created via command line) detected under the same causality chain.

**Attacker's Goals**

Perform multiple activities to achieve the attacker's goals in the target environment.

**Investigative actions**

* Investigate the causality of these alerts.
* Track down other suspicious activity under this causality.

</details>

<details>

<summary>AI-determined combination of risky alerts under the same causality: interface enumeration using netsh, possible arp reconnaissance, new service created via command line</summary>

**Synopsis**

| Field             | Value                                      |
| ----------------- | ------------------------------------------ |
| ATT\&CK Tactic    | Execution (TA0002)                         |
| ATT\&CK Technique | User Execution (T1204), Native API (T1106) |
| Severity          | Medium                                     |

**Description**

A combination of alerts (interface enumeration using netsh, possible arp reconnaissance, new service created via command line) detected under the same causality chain.

**Attacker's Goals**

Perform multiple activities to achieve the attacker's goals in the target environment.

**Investigative actions**

* Investigate the causality of these alerts.
* Track down other suspicious activity under this causality.

</details>

<details>

<summary>AI-determined combination of risky alerts under the same causality: task scheduled by commonly abused host process, powershell running with download in the command line, powershell calling invoke expression argument</summary>

**Synopsis**

| Field             | Value                                      |
| ----------------- | ------------------------------------------ |
| ATT\&CK Tactic    | Execution (TA0002)                         |
| ATT\&CK Technique | User Execution (T1204), Native API (T1106) |
| Severity          | Medium                                     |

**Description**

A combination of alerts (task scheduled by commonly abused host process, powershell running with download in the command line, powershell calling invoke expression argument) detected under the same causality chain.

**Attacker's Goals**

Perform multiple activities to achieve the attacker's goals in the target environment.

**Investigative actions**

* Investigate the causality of these alerts.
* Track down other suspicious activity under this causality.

</details>

<details>

<summary>AI-determined combination of risky alerts under the same causality: Defender manipulation with new service creation and unsigned temp process</summary>

**Synopsis**

| Field             | Value                                      |
| ----------------- | ------------------------------------------ |
| ATT\&CK Tactic    | Execution (TA0002)                         |
| ATT\&CK Technique | User Execution (T1204), Native API (T1106) |
| Severity          | Medium                                     |

**Description**

Manipulation of Windows Defender configuration, a new service created via command line, and an unsigned process running from a temporary directory under the same causality chain.

**Attacker's Goals**

Perform multiple activities to achieve the attacker's goals in the target environment.

**Investigative actions**

* Investigate the causality of these alerts.
* Track down other suspicious activity under this causality.

</details>

<details>

<summary>AI-determined combination of risky alerts under the same causality: PowerShell download with suspicious command line and unsigned temp process</summary>

**Synopsis**

| Field             | Value                                      |
| ----------------- | ------------------------------------------ |
| ATT\&CK Tactic    | Execution (TA0002)                         |
| ATT\&CK Technique | User Execution (T1204), Native API (T1106) |
| Severity          | Medium                                     |

**Description**

PowerShell running with download in the command line, combined with a suspicious PowerShell command line and an unsigned process running from a temporary directory under the same causality chain.

**Attacker's Goals**

Perform multiple activities to achieve the attacker's goals in the target environment.

**Investigative actions**

* Investigate the causality of these alerts.
* Track down other suspicious activity under this causality.

</details>

<details>

<summary>AI-determined combination of risky alerts under the same causality: ping loopback with PowerShell admin attempt and unsigned temp process</summary>

**Synopsis**

| Field             | Value                                      |
| ----------------- | ------------------------------------------ |
| ATT\&CK Tactic    | Execution (TA0002)                         |
| ATT\&CK Technique | User Execution (T1204), Native API (T1106) |
| Severity          | Medium                                     |

**Description**

Ping executed with loopback address, PowerShell possibly attempting to execute as administrator, and an unsigned process running from a temporary directory under the same causality chain.

**Attacker's Goals**

Perform multiple activities to achieve the attacker's goals in the target environment.

**Investigative actions**

* Investigate the causality of these alerts.
* Track down other suspicious activity under this causality.

</details>

<details>

<summary>AI-determined combination of risky alerts under the same causality: AD enumeration with new service creation and unsigned temp process</summary>

**Synopsis**

| Field             | Value                                      |
| ----------------- | ------------------------------------------ |
| ATT\&CK Tactic    | Execution (TA0002)                         |
| ATT\&CK Technique | User Execution (T1204), Native API (T1106) |
| Severity          | Medium                                     |

**Description**

Active directory enumeration using nltest.exe, a new service created via command line, and an unsigned process running from a temporary directory under the same causality chain.

**Attacker's Goals**

Perform multiple activities to achieve the attacker's goals in the target environment.

**Investigative actions**

* Investigate the causality of these alerts.
* Track down other suspicious activity under this causality.

</details>

<details>

<summary>AI-determined combination of risky alerts under the same causality: AD enumeration with PsExec remote execution and unsigned temp process</summary>

**Synopsis**

| Field             | Value                                      |
| ----------------- | ------------------------------------------ |
| ATT\&CK Tactic    | Execution (TA0002)                         |
| ATT\&CK Technique | User Execution (T1204), Native API (T1106) |
| Severity          | Medium                                     |

**Description**

Active directory enumeration using nltest.exe, PsExec executing a command from a remote host, and an unsigned process running from a temporary directory under the same causality chain.

**Attacker's Goals**

Perform multiple activities to achieve the attacker's goals in the target environment.

**Investigative actions**

* Investigate the causality of these alerts.
* Track down other suspicious activity under this causality.

</details>

<details>

<summary>AI-determined combination of risky alerts under the same causality: MSBuild execution with boot config modification and unsigned temp process</summary>

**Synopsis**

| Field             | Value                                      |
| ----------------- | ------------------------------------------ |
| ATT\&CK Tactic    | Execution (TA0002)                         |
| ATT\&CK Technique | User Execution (T1204), Native API (T1106) |
| Severity          | Medium                                     |

**Description**

MSBuild execution, modification of Windows boot configuration using bcdedit.exe, and an unsigned process running from a temporary directory under the same causality chain.

**Attacker's Goals**

Perform multiple activities to achieve the attacker's goals in the target environment.

**Investigative actions**

* Investigate the causality of these alerts.
* Track down other suspicious activity under this causality.

</details>

<details>

<summary>AI-determined combination of risky alerts under the same causality: modification of Windows boot configuration using bcdedit exe, execution of regsvcs regasm with uncommon paths</summary>

**Synopsis**

| Field             | Value                                      |
| ----------------- | ------------------------------------------ |
| ATT\&CK Tactic    | Execution (TA0002)                         |
| ATT\&CK Technique | User Execution (T1204), Native API (T1106) |
| Severity          | Medium                                     |

**Description**

A combination of alerts (modification of Windows boot configuration using bcdedit exe, execution of regsvcs regasm with uncommon paths) detected under the same causality chain.

**Attacker's Goals**

Perform multiple activities to achieve the attacker's goals in the target environment.

**Investigative actions**

* Investigate the causality of these alerts.
* Track down other suspicious activity under this causality.

</details>

<details>

<summary>AI-determined combination of risky alerts under the same causality: rundll32 loads a known abused dll, execution of regsvcs regasm with uncommon paths</summary>

**Synopsis**

| Field             | Value                                      |
| ----------------- | ------------------------------------------ |
| ATT\&CK Tactic    | Execution (TA0002)                         |
| ATT\&CK Technique | User Execution (T1204), Native API (T1106) |
| Severity          | Medium                                     |

**Description**

A combination of alerts (rundll32 loads a known abused dll, execution of regsvcs regasm with uncommon paths) detected under the same causality chain.

**Attacker's Goals**

Perform multiple activities to achieve the attacker's goals in the target environment.

**Investigative actions**

* Investigate the causality of these alerts.
* Track down other suspicious activity under this causality.

</details>

<details>

<summary>AI-determined combination of risky alerts under the same causality: changing permissions or ownership of a file or folder, bitsadmin exe used to download data</summary>

**Synopsis**

| Field             | Value                                      |
| ----------------- | ------------------------------------------ |
| ATT\&CK Tactic    | Execution (TA0002)                         |
| ATT\&CK Technique | User Execution (T1204), Native API (T1106) |
| Severity          | Medium                                     |

**Description**

A combination of alerts (changing permissions or ownership of a file or folder, bitsadmin exe used to download data) detected under the same causality chain.

**Attacker's Goals**

Perform multiple activities to achieve the attacker's goals in the target environment.

**Investigative actions**

* Investigate the causality of these alerts.
* Track down other suspicious activity under this causality.

</details>

<details>

<summary>AI-determined combination of risky alerts under the same causality: new service created via command line, powershell creates a new service</summary>

**Synopsis**

| Field             | Value                                      |
| ----------------- | ------------------------------------------ |
| ATT\&CK Tactic    | Execution (TA0002)                         |
| ATT\&CK Technique | User Execution (T1204), Native API (T1106) |
| Severity          | Medium                                     |

**Description**

A combination of alerts (new service created via command line, powershell creates a new service) detected under the same causality chain.

**Attacker's Goals**

Perform multiple activities to achieve the attacker's goals in the target environment.

**Investigative actions**

* Investigate the causality of these alerts.
* Track down other suspicious activity under this causality.

</details>

<details>

<summary>AI-determined combination of risky alerts under the same causality: a scripting engine was called to run in command line, suspicious powershell command line</summary>

**Synopsis**

| Field             | Value                                      |
| ----------------- | ------------------------------------------ |
| ATT\&CK Tactic    | Execution (TA0002)                         |
| ATT\&CK Technique | User Execution (T1204), Native API (T1106) |
| Severity          | Medium                                     |

**Description**

A combination of alerts (a scripting engine was called to run in command line, suspicious powershell command line) detected under the same causality chain.

**Attacker's Goals**

Perform multiple activities to achieve the attacker's goals in the target environment.

**Investigative actions**

* Investigate the causality of these alerts.
* Track down other suspicious activity under this causality.

</details>

<details>

<summary>AI-determined combination of risky alerts under the same causality: modification of Windows boot configuration using bcdedit.exe and msbuild.exe execution</summary>

**Synopsis**

| Field             | Value                                      |
| ----------------- | ------------------------------------------ |
| ATT\&CK Tactic    | Execution (TA0002)                         |
| ATT\&CK Technique | User Execution (T1204), Native API (T1106) |
| Severity          | Medium                                     |

**Description**

A combination of alerts (modification of Windows boot configuration using bcdedit.exe and msbuild.exe execution) detected under the same causality chain.

**Attacker's Goals**

Perform multiple activities to achieve the attacker's goals in the target environment.

**Investigative actions**

* Investigate the causality of these alerts.
* Track down other suspicious activity under this causality.

</details>

<details>

<summary>AI-determined combination of risky alerts under the same causality: manipulation of bootexecute registry run key, dumping registry hives with passwords</summary>

**Synopsis**

| Field             | Value                                      |
| ----------------- | ------------------------------------------ |
| ATT\&CK Tactic    | Execution (TA0002)                         |
| ATT\&CK Technique | User Execution (T1204), Native API (T1106) |
| Severity          | Medium                                     |

**Description**

A combination of alerts (manipulation of bootexecute registry run key, dumping registry hives with passwords) detected under the same causality chain.

**Attacker's Goals**

Perform multiple activities to achieve the attacker's goals in the target environment.

**Investigative actions**

* Investigate the causality of these alerts.
* Track down other suspicious activity under this causality.

</details>

<details>

<summary>AI-determined combination of risky alerts under the same causality: uncommon local scheduled task creation via schtasks exe, suspicious powershell command line</summary>

**Synopsis**

| Field             | Value                                      |
| ----------------- | ------------------------------------------ |
| ATT\&CK Tactic    | Execution (TA0002)                         |
| ATT\&CK Technique | User Execution (T1204), Native API (T1106) |
| Severity          | Medium                                     |

**Description**

A combination of alerts (uncommon local scheduled task creation via schtasks exe, suspicious powershell command line) detected under the same causality chain.

**Attacker's Goals**

Perform multiple activities to achieve the attacker's goals in the target environment.

**Investigative actions**

* Investigate the causality of these alerts.
* Track down other suspicious activity under this causality.

</details>

<details>

<summary>AI-determined combination of risky alerts under the same causality: ping loopback with shadow copy access</summary>

**Synopsis**

| Field             | Value                                      |
| ----------------- | ------------------------------------------ |
| ATT\&CK Tactic    | Execution (TA0002)                         |
| ATT\&CK Technique | User Execution (T1204), Native API (T1106) |
| Severity          | Medium                                     |

**Description**

Ping with loopback address combined with WMI shadow copy access under the same causality chain.

**Attacker's Goals**

Perform multiple activities to achieve the attacker's goals in the target environment.

**Investigative actions**

* Investigate the causality of these alerts.
* Track down other suspicious activity under this causality.

</details>

<details>

<summary>AI-determined combination of risky alerts under the same causality: Defender manipulation with shadow copy access</summary>

**Synopsis**

| Field             | Value                                      |
| ----------------- | ------------------------------------------ |
| ATT\&CK Tactic    | Execution (TA0002)                         |
| ATT\&CK Technique | User Execution (T1204), Native API (T1106) |
| Severity          | Medium                                     |

**Description**

Manipulation of Windows Defender configuration combined with WMI access to the shadow copy interface under the same causality chain.

**Attacker's Goals**

Perform multiple activities to achieve the attacker's goals in the target environment.

**Investigative actions**

* Investigate the causality of these alerts.
* Track down other suspicious activity under this causality.

</details>

<details>

<summary>AI-determined combination of risky alerts under the same causality: AD enumeration with Windows Defender manipulation</summary>

**Synopsis**

| Field             | Value                                      |
| ----------------- | ------------------------------------------ |
| ATT\&CK Tactic    | Execution (TA0002)                         |
| ATT\&CK Technique | User Execution (T1204), Native API (T1106) |
| Severity          | Medium                                     |

**Description**

Active directory enumeration using nltest.exe combined with manipulation of Windows Defender configuration under the same causality chain.

**Attacker's Goals**

Perform multiple activities to achieve the attacker's goals in the target environment.

**Investigative actions**

* Investigate the causality of these alerts.
* Track down other suspicious activity under this causality.

</details>

<details>

<summary>AI-determined combination of risky alerts under the same causality: new service creation with shadow copy access</summary>

**Synopsis**

| Field             | Value                                      |
| ----------------- | ------------------------------------------ |
| ATT\&CK Tactic    | Execution (TA0002)                         |
| ATT\&CK Technique | User Execution (T1204), Native API (T1106) |
| Severity          | Medium                                     |

**Description**

A new service created via command line combined with WMI access to the shadow copy interface under the same causality chain.

**Attacker's Goals**

Perform multiple activities to achieve the attacker's goals in the target environment.

**Investigative actions**

* Investigate the causality of these alerts.
* Track down other suspicious activity under this causality.

</details>

<details>

<summary>AI-determined combination of risky alerts under the same causality: PowerShell download with shadow copy access</summary>

**Synopsis**

| Field             | Value                                      |
| ----------------- | ------------------------------------------ |
| ATT\&CK Tactic    | Execution (TA0002)                         |
| ATT\&CK Technique | User Execution (T1204), Native API (T1106) |
| Severity          | Medium                                     |

**Description**

PowerShell running with download in the command line combined with WMI access to the shadow copy interface under the same causality chain.

**Attacker's Goals**

Perform multiple activities to achieve the attacker's goals in the target environment.

**Investigative actions**

* Investigate the causality of these alerts.
* Track down other suspicious activity under this causality.

</details>

<details>

<summary>AI-determined combination of risky alerts under the same causality: BootExecute manipulation with shadow copy access</summary>

**Synopsis**

| Field             | Value                                      |
| ----------------- | ------------------------------------------ |
| ATT\&CK Tactic    | Execution (TA0002)                         |
| ATT\&CK Technique | User Execution (T1204), Native API (T1106) |
| Severity          | Medium                                     |

**Description**

Manipulation of the BootExecute Registry run key combined with WMI access to the shadow copy interface under the same causality chain.

**Attacker's Goals**

Perform multiple activities to achieve the attacker's goals in the target environment.

**Investigative actions**

* Investigate the causality of these alerts.
* Track down other suspicious activity under this causality.

</details>

<details>

<summary>AI-determined combination of risky alerts under the same causality: task scheduled by commonly abused host process, commonly abused process executed with obfuscated characters, powershell running with download in the command line, suspicious powershell command line</summary>

**Synopsis**

| Field             | Value                                      |
| ----------------- | ------------------------------------------ |
| ATT\&CK Tactic    | Execution (TA0002)                         |
| ATT\&CK Technique | User Execution (T1204), Native API (T1106) |
| Severity          | Low                                        |

**Description**

A combination of alerts (task scheduled by commonly abused host process, commonly abused process executed with obfuscated characters, powershell running with download in the command line, suspicious powershell command line) detected under the same causality chain.

**Attacker's Goals**

Perform multiple activities to achieve the attacker's goals in the target environment.

**Investigative actions**

* Investigate the causality of these alerts.
* Track down other suspicious activity under this causality.

</details>

<details>

<summary>AI-determined combination of risky alerts under the same causality: powershell script executed from a temporary directory, possible arp reconnaissance, unsigned process running from a temporary directory</summary>

**Synopsis**

| Field             | Value                                      |
| ----------------- | ------------------------------------------ |
| ATT\&CK Tactic    | Execution (TA0002)                         |
| ATT\&CK Technique | User Execution (T1204), Native API (T1106) |
| Severity          | Low                                        |

**Description**

A combination of alerts (powershell script executed from a temporary directory, possible arp reconnaissance, unsigned process running from a temporary directory) detected under the same causality chain.

**Attacker's Goals**

Perform multiple activities to achieve the attacker's goals in the target environment.

**Investigative actions**

* Investigate the causality of these alerts.
* Track down other suspicious activity under this causality.

</details>

<details>

<summary>AI-determined combination of risky alerts under the same causality: active directory enumeration using built in nltest exe, suspicious setspn exe execution</summary>

**Synopsis**

| Field             | Value                                      |
| ----------------- | ------------------------------------------ |
| ATT\&CK Tactic    | Execution (TA0002)                         |
| ATT\&CK Technique | User Execution (T1204), Native API (T1106) |
| Severity          | Low                                        |

**Description**

A combination of alerts (active directory enumeration using built in nltest exe, suspicious setspn exe execution) detected under the same causality chain.

**Attacker's Goals**

Perform multiple activities to achieve the attacker's goals in the target environment.

**Investigative actions**

* Investigate the causality of these alerts.
* Track down other suspicious activity under this causality.

</details>

<details>

<summary>AI-determined combination of risky alerts under the same causality: suspicious powershell command line, unsigned process running from a temporary directory</summary>

**Synopsis**

| Field             | Value                                      |
| ----------------- | ------------------------------------------ |
| ATT\&CK Tactic    | Execution (TA0002)                         |
| ATT\&CK Technique | User Execution (T1204), Native API (T1106) |
| Severity          | Low                                        |

**Description**

A combination of alerts (suspicious powershell command line, unsigned process running from a temporary directory) detected under the same causality chain.

**Attacker's Goals**

Perform multiple activities to achieve the attacker's goals in the target environment.

**Investigative actions**

* Investigate the causality of these alerts.
* Track down other suspicious activity under this causality.

</details>

<details>

<summary>AI-determined combination of risky alerts under the same causality: active directory enumeration using built in nltest exe, powershell running with download in the command line</summary>

**Synopsis**

| Field             | Value                                      |
| ----------------- | ------------------------------------------ |
| ATT\&CK Tactic    | Execution (TA0002)                         |
| ATT\&CK Technique | User Execution (T1204), Native API (T1106) |
| Severity          | Low                                        |

**Description**

A combination of alerts (active directory enumeration using built in nltest exe, powershell running with download in the command line) detected under the same causality chain.

**Attacker's Goals**

Perform multiple activities to achieve the attacker's goals in the target environment.

**Investigative actions**

* Investigate the causality of these alerts.
* Track down other suspicious activity under this causality.

</details>

<details>

<summary>AI-determined combination of risky alerts under the same causality: suspicious powershell command line, powershell calling invoke expression argument</summary>

**Synopsis**

| Field             | Value                                      |
| ----------------- | ------------------------------------------ |
| ATT\&CK Tactic    | Execution (TA0002)                         |
| ATT\&CK Technique | User Execution (T1204), Native API (T1106) |
| Severity          | Low                                        |

**Description**

A combination of alerts (suspicious powershell command line, powershell calling invoke expression argument) detected under the same causality chain.

**Attacker's Goals**

Perform multiple activities to achieve the attacker's goals in the target environment.

**Investigative actions**

* Investigate the causality of these alerts.
* Track down other suspicious activity under this causality.

</details>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/ai-determined-combination-of-risky-alerts-under-the-same-causality.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
