Possible brute force or configuration change attempt on cytool
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
1 Hour
Deduplication Period
1 Day
Required Data
XDR Agent
ATT&CK Tactic
Credential Access (TA0006)
ATT&CK Technique
Brute Force: Password Guessing (T1110.001)
Severity
High
Description
An unusual amount of cytool commands were executed in a short period from a user who doesn't usually run these commands. This may indicate an attempt to guess the Administrator password.
Attacker's Goals
The attacker may disable the agent to perform malicious activities.
Investigative actions
Verify which user ran these commands and if it is a legitimate behavior on this host.
PreviousPossible brute force on sudo user
NextPossible code downloading from a remote host by Regsvr32
Was this helpful?
