Added - Content Update Release Notes - Cortex - Cortex

Analytics Content Version: 2026.02.18

Product
Cortex
Creation date
2026-03-01
Last date published
2026-03-01
Category
Content Update Release Notes

[Informational] Uncommon net group command execution

  • [High] Uncommon unsigned net group administrators command execution

  • [High] Uncommon unsigned net group administrators command execution - fixed localization issues

  • [Medium] Uncommon administrator net group execution by scripting engine or command prompt

  • [Medium] Uncommon net group administrators command execution

  • [Low] Uncommon net group execution

  • [Low] Uncommon remote net group administrators command execution

  • [Low] Uncommon remote net group execution

[Informational] Uncommon access to /etc/passwd

  • [Medium] Uncommon access to /etc/passwd by a potential Webshell

  • [Medium] Uncommon access to /etc/passwd by a potentially known credential dumper or enumeration script

  • [Medium] Uncommon access to /etc/passwd by a security testing tool

  • [Low] Uncommon access to /etc/passwd from temporary or world writable directories

  • [Low] Uncommon access to /etc/passwd using an interactive binary

  • [Low] Uncommon access to /etc/passwd using an interactive shell

  • [Low] Uncommon access to /etc/passwd via a new inline bash script

  • [Low] Uncommon access to /etc/passwd with additional sensitive files in the command line

  • [Low] Uncommon access to /etc/passwd with both /etc/passwd and /etc/shadow in the command line

  • [Low] Uncommon access to /etc/passwd, involving a network utility

  • [Low] Uncommon link creation to /etc/passwd

[Informational] Uncommon net localgroup command execution

  • [Medium] Uncommon net localgroup administrators command execution by a web server process or CGO

  • [Medium] Uncommon remote net localgroup execution

  • [Medium] Uncommon unsigned net localgroup administrators command execution

  • [Medium] Uncommon unsigned net localgroup administrators command execution - fixed localization issues

  • [Low] Uncommon administrator net localgroup execution by scripting engine or command prompt

  • [Low] Uncommon net localgroup administrators command execution

  • [Low] Uncommon net localgroup execution

[Informational] LOLBAS executable injects into another process

  • [Low] LOLBAS executable injects into another process under an uncommon CGO