Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters. technique: T1496 ✕

Download CSV Show ATT&CK heatmap
  • A Possible crypto miner was detected on a host Medium

    The host produced traffic consistent with the crypto mining.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Impact (TA0040)
    ATT&CK techniques: Resource Hijacking (T1496)
    Required data: Palo Alto Networks Firewall traffic Logs XDR Agent
    Attacker's goals: Abuse resources to mine crypto coins.
    Investigative actions: Check the host for crypto mining client software. Look for differences in the resource consumption from this host. Examine the client's network traffic for suspicious domains affiliated with mining or mining pools.