Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source
  • A disabled user attempted to log in Informational Identity Analytics 1 variation

    A disabled user attempted to log in.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Initial Access (TA0001)
    ATT&CK techniques: Valid Accounts: Domain Accounts (T1078.002)
    Required data: XDR Agent
    Attacker's goals: Use an account that was possibly compromised in the past to gain access to the network.
    Investigative actions: Confirm that the activity is benign (e.g. the user was recently enabled by an authorized entity). Check whether you have issues with your Cloud Identity Engine failing to sync data from Active Directory. Monitor services that may be running with a disabled user's credentials.

    Variations

    Cached interactive login attempt by a disabled user

    Informational overridden

    A disabled user attempted to log in. overridden

  • A disabled user attempted to log in to a VPN Low Identity Analytics 1 variation

    A disabled user attempted to log in suspiciously to a VPN.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Initial Access (TA0001)
    ATT&CK techniques: Valid Accounts: Domain Accounts (T1078.002)
    Required data: Palo Alto Networks Global Protect Third-Party VPNs
    Attacker's goals: Use an account that was possibly compromised in the past to gain access to the network.
    Investigative actions: See whether the service authentication was successful. Confirm that the activity is benign (e.g. a contractor user). Check whether you have issues with your Cloud Identity Engine failing to sync data from Active Directory.

    Variations

    Possible VPN login attempt by disabled user

    Informational overridden

    A disabled user attempted to log in suspiciously to a VPN. overridden