Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. Cortex XDR:

Cortex XDR:

Scheduled Pinned Locked Moved Uncategorized
2 Posts 2 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • kajer@infosec.exchangeK This user is from outside of this forum
    kajer@infosec.exchangeK This user is from outside of this forum
    kajer@infosec.exchange
    wrote last edited by
    #1

    Cortex XDR:

    OMG IT'S UNAME!@?!?!?!

    Alert Name: Uncommon Linux shell command execution trying to gather information about the system
    Alert id: [redacted]
    Severity: Low
    Source: XDR Analytics BIOC
    Category: Execution
    Action: Detected
    Description: The process bambu-studio has executed a shell command using the sh shell interpreter. This type of process spawning this shell is uncommon in the organization. The potential risks include exploitation of a legitimate process or malware that executes shell commands. The combination of both child and parent was seen on 0 different hosts across 0 unique days in the last 30 days. The shell command is gathering information about the host system. The full executed command line is: sh -c -- uname -r 2>/dev/null
    Host: [redacted]
    Username: [redacted]
    chaz@infosec.exchangeC 1 Reply Last reply
    0
    • kajer@infosec.exchangeK kajer@infosec.exchange

      Cortex XDR:

      OMG IT'S UNAME!@?!?!?!

      Alert Name: Uncommon Linux shell command execution trying to gather information about the system
      Alert id: [redacted]
      Severity: Low
      Source: XDR Analytics BIOC
      Category: Execution
      Action: Detected
      Description: The process bambu-studio has executed a shell command using the sh shell interpreter. This type of process spawning this shell is uncommon in the organization. The potential risks include exploitation of a legitimate process or malware that executes shell commands. The combination of both child and parent was seen on 0 different hosts across 0 unique days in the last 30 days. The shell command is gathering information about the host system. The full executed command line is: sh -c -- uname -r 2>/dev/null
      Host: [redacted]
      Username: [redacted]
      chaz@infosec.exchangeC This user is from outside of this forum
      chaz@infosec.exchangeC This user is from outside of this forum
      chaz@infosec.exchange
      wrote last edited by
      #2

      @kajer The infamous hacker known only as uname strikes again!

      1 Reply Last reply
      1
      0
      • R relay@relay.infosec.exchange shared this topic
      Reply
      • Reply as topic
      Log in to reply
      • Oldest to Newest
      • Newest to Oldest
      • Most Votes


      • Login

      • Login or register to search.
      • First post
        Last post
      0
      • Categories
      • Recent
      • Tags
      • Popular
      • World
      • Users
      • Groups