Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source
  • Abnormal connections to a dormant host from a newly seen endpoint Informational 1 variation

    The endpoint has performed multiple connections to an endpoint that is relatively inactive on the network.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    6 Hours
    Deduplication:
    1 Day
    ATT&CK tactics: Discovery (TA0007)
    ATT&CK techniques: Remote System Discovery (T1018)
    Required data: Palo Alto Networks Firewall traffic Logs XDR Agent
    Attacker's goals: While probing the network, an attacker may discover dormant hosts. These inactive systems can then be used for lateral movement or privilege escalation.
    Investigative actions: Validate that the source is not a sanctioned port scanner. Check for suspicious artifacts in the endpoint profile.

    Variations

    Abnormal connections to a dormant host

    Low overridden

    The endpoint has performed multiple connections to an endpoint that is relatively inactive on the network. overridden