Windows CGO, actor and action processes with anomalous characteristics

Cortex XDR Analytics Alert Reference by data source

Product
Cortex XDR
Last date published
2026-06-15
Category
Analytics Alert Reference
Index by
data source

Synopsis

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

  • Requires:
    • XDR Agent

Detection Modules

Detector Tags

Process Anomaly Analytics

ATT&CK Tactic

Execution (TA0002)

ATT&CK Technique

User Execution (T1204)

Severity

Informational

Description

Windows CGO, actor and action processes with anomalous characteristics.

Attacker's Goals

  • Processes anomalous characteristics which commonly appear in malicious activities.

Investigative actions

  • Investigate the executed process image and check if it is malicious.
  • Investigate the CGO and actor processes that executed the process and check if they are malicious.

Variations

Windows CGO, actor and action processes with anomalous characteristics by an untrusted CGO

Synopsis

ATT&CK Tactic

Execution (TA0002)

ATT&CK Technique

User Execution (T1204)

Severity

Low

Description

Windows CGO, actor and action processes with anomalous characteristics by an untrusted CGO.

Attacker's Goals

  • Processes anomalous characteristics which commonly appear in malicious activities.

Investigative actions

  • Investigate the executed process image and check if it is malicious.
  • Investigate the CGO and actor processes that executed the process and check if they are malicious.


Windows CGO, actor and action processes with highly anomalous characteristics

Synopsis

ATT&CK Tactic

Execution (TA0002)

ATT&CK Technique

User Execution (T1204)

Severity

Low

Description

Windows CGO, actor and action processes with anomalous characteristics.

Attacker's Goals

  • Processes anomalous characteristics which commonly appear in malicious activities.

Investigative actions

  • Investigate the executed process image and check if it is malicious.
  • Investigate the CGO and actor processes that executed the process and check if they are malicious.