Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters.

Download CSV Show ATT&CK heatmap
  • AI-determined combination of risky alerts under the same actor process Informational 1 variation

    Multiple alerts likely to be associated with an incident were identified under the same actor process.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    12 Hours
    Deduplication:
    1 Day
    ATT&CK tactics: Execution (TA0002)
    ATT&CK techniques: User Execution (T1204) Native API (T1106)
    Required data: Palo Alto Networks Platform Alerts Third-Party Alerts
    Detector tags: AI Insight Fusion Analytics
    Attacker's goals: Perform multiple activities to achieve the attacker's goals in the target environment.
    Investigative actions: Investigate the actor process of these alerts. Track down other suspicious activity under this actor process.

    Variations

    AI-determined combination of risky alerts under the same actor process: LDAP traffic from non-standard process with SMB traffic from non-standard process

    Medium overridden

    A non-standard process communicated over LDAP ports, combined with SMB traffic from a non-standard process under the same actor process. This combination may indicate an attacker performing Active Directory enumeration while leveraging SMB for lateral movement or discovery. overridden