Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters.
Download CSV Show ATT&CK heatmapAbnormal connections to a dormant host from a newly seen endpoint Informational 1 variation
The endpoint has performed multiple connections to an endpoint that is relatively inactive on the network.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- 6 Hours
- Deduplication:
- 1 Day
ATT&CK tactics: Discovery (TA0007)ATT&CK techniques: Remote System Discovery (T1018)Required data: Palo Alto Networks Firewall traffic Logs XDR AgentAttacker's goals: While probing the network, an attacker may discover dormant hosts. These inactive systems can then be used for lateral movement or privilege escalation.Investigative actions: Validate that the source is not a sanctioned port scanner. Check for suspicious artifacts in the endpoint profile.Variations
Abnormal connections to a dormant host
Low overridden
The endpoint has performed multiple connections to an endpoint that is relatively inactive on the network. overridden