Skip to main content
Skip table of contents

Cortex Alert Messages

Vendor Documentation

Classification

Rule Name

Rule Type

Common Event

Classification
Cortex Alert MessagesBase RuleGeneral SecurityOther Security
Command And Control DetectedSub RuleSuspicious ActivitySuspicious
Discovery DetectedSub RuleSuspicious ActivitySuspicious
Persistence DetectedSub RuleSuspicious ActivitySuspicious
Execution DetectedSub RuleArbitrary Code ExecutionAttack
Impact DetectedSub RuleSuspicious ActivitySuspicious
Lateral Movement DetectedSub RuleSuspicious ActivitySuspicious
Credential Access DetectedSub RuleSuspicious ActivitySuspicious
Defense Evasion DetectedSub RuleSuspicious ActivitySuspicious
Initial Access DetectedSub RuleSuspicious ActivitySuspicious
Collection DetectedSub RuleSuspicious ActivitySuspicious
Exfiltration DetectedSub RuleSuspicious ActivitySuspicious
Privilege Escalation DetectedSub RuleUnauthorized ActivityMisuse
Virus DetectedSub RuleDetected Virus ActivityMalware
Spyware DetectedSub RuleDetected Spyware ActivityMalware
Vulnerability DetectedSub RuleGeneral Security AlertWarning
URL Filtering DetectedSub RuleGeneral WebFilter URLFilter CriticalCritical
File Blocking DetectedSub RuleDevice BlockedWarning
Zone Protection DetectedSub RuleDetected Spyware ActivityMalware
DoS  DetectedSub RuleNetwork Denial Of ServiceDenial Of Service
Data Filtering DetectedSub RuleDetected Spyware ActivityMalware
Wildfire Analysis DetectedSub RuleSuspicious ActivitySuspicious
Discovery PreventedSub RuleFailed Suspicious ActivityFailed Suspicious
Command And Control PreventedSub RuleFailed Suspicious ActivityFailed Suspicious
Persistence PreventedSub RuleFailed Suspicious ActivityFailed Suspicious
Execution PreventedSub RuleFailed Arbitrary Code ExecutionFailed Attack
Impact PreventedSub RuleFailed Suspicious ActivityFailed Suspicious
Lateral Movement PreventedSub RuleFailed Suspicious ActivityFailed Suspicious
Credential Access PreventedSub RuleFailed Suspicious ActivityFailed Suspicious
Defense Evasion PreventedSub RuleFailed Suspicious ActivityFailed Suspicious
Initial Access PreventedSub RuleFailed Suspicious ActivityFailed Suspicious
Collection PreventedSub RuleFailed Suspicious ActivityFailed Suspicious
Exfiltration PreventedSub RuleFailed Suspicious ActivityFailed Suspicious
Privilege Escalation PreventedSub RuleFailed Unauthorized ActivityFailed Misuse
Virus PreventedSub RuleFailed Virus ActivityFailed Malware
Spyware PreventedSub RuleFailed Spyware ActivityFailed Malware
Vulnerability PreventedSub RuleFailed Suspicious ActivityFailed Suspicious
URL Filtering PreventedSub RuleFailed Suspicious ActivityFailed Suspicious
File Blocking PreventedSub RuleBlocked MessageFailed Activity
Zone Protection PreventedSub RuleFailed Suspicious ActivityFailed Suspicious
DoS Protection PreventedSub RuleFailed Network Denial Of ServiceFailed Denial of Service
Data Filtering PreventedSub RuleFailed Suspicious ActivityFailed Suspicious
Wildfire Analysis PreventedSub RuleFailed Suspicious ActivityFailed Suspicious

Mapping with LogRhythm Schema 

Device Key in Log MessageLogRhythm SchemaData TypeSchema Description
HEADER/VendorN/AN/ADevice Vendor
HEADER/Device ProductN/AN/ADevice Product
HEADER/Device Version<version>Text/StringProduct Version
HEADER/Device Event Class ID<vmid> Text/StringDevice Event Class ID
HEADER/name<vendorinfo>Text/StringName of the event
HEADER/Severity<severity>Number

Severity:

0 - Unknown
6 - Low
8 - Medium
9 - High

endN/A N/ATimestamp
shost<sname>Text/StringSource Host
suser<domainorigin>
<login>
Text/StringSource User
deviceFacilityN/A N/AN/A 
cat<threatname>Text/StringCategory
externalId<threatid> NumberN/A 
request<url>Text/String/NumberLink to XDR alert page
cs1<process>Text/StringThe name of the process that initiated an activity such as a network connection or registry change.
cs1LabelN/A N/AN/A 
cs2<command>Text/StringCommand-line used to initiate the process including any arguments.
cs2LabelN/A N/AN/A 
cs3<status>Text/String

Signing status of the process that initiated the activity:

Unsigned
Signed
Invalid Signature
Unknown

cs3LabelN/A N/AN/A 
cs4<parentprocessname>Text/StringThe name of the process that started the causality chain based on Cortex XDR causality logic.
cs4LabelN/A N/AN/A 
cs5N/A N/ACommand-line arguments of the Causality Group Owner.
cs5LabelN/A N/AN/A 
cs6N/A N/A

Signing status of the CGO:

Unsigned
Signed
Invalid Signature
Unknown

cs6LabelN/A N/AN/A 
dst<dip>IP AddressDestination IP
dpt<dport>NumberDestination Port
src<sip>IP AddressSource IP
spt<sport>NumberSource Port
app<protname>Text/StringApplication Used
fileHash<hash>Text/StringHash value of the file.
filePath<object>Text/StringWhen the alert triggered on a file (the Event Type is File) this is the path to the file on the endpoint. If not, then N/A.
targetprocesssignatureN/A N/AN/A 
tenantnameN/A N/AN/A 
tenantCDLidN/A N/AN/A 
CSPaccountnameN/A N/AN/A 
initiatorSha256<hash>Text/StringThe SHA256 hash value of the initiator.
initiatorPathN/A N/APath of the initiating process.
cgoSha256N/A N/AThe SHA256 value of the CGO that initiated the alert.
osParentNameN/A N/AN/A 
osParentCmdN/A N/ACommand-line used to by the parent operating system to initiate the process including any arguments.
osParentSignatureN/A N/A

Signing status of the operating system of the activity:

Unsigned
Signed
Invalid Signature
Unknown

osParentSignerN/A N/AParent operating system signer.
incident<reason>NumberThe ID of the any incident that includes the alert.
act<action>
<tag1>
Text/StringAction taken by the alert sensor, either Detected or Prevented with action status displayed in parenthesis.
srcZoneNameN/AN/ASource Zone Name
dstZoneNameN/AN/ADestination Zone Name
fwNameN/AN/AFirewall Name
msg<subject>Text/StringMessage
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.