Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters.

Download CSV Show ATT&CK heatmap
  • A user logged in at an unusual time via VPN Informational Identity Analytics

    A user connected to a VPN on a day and hour, which is unusual for this user. This may indicate that the account was compromised.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Hour
    ATT&CK tactics: Defense Evasion (TA0005)
    ATT&CK techniques: Valid Accounts (T1078)
    Required data: Palo Alto Networks Global Protect Third-Party VPNs
    Attacker's goals: An attacker is attempting to evade detection.
    Investigative actions: Check the amount of traffic and how long it continues. Follow further actions done by the user.