Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters.

Download CSV Show ATT&CK heatmap
  • Abnormal network communication through TOR using an uncommon port Low 2 variations

    Suspicious connection from a known TOR IP to an uncommon port.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Command and Control (TA0011)
    ATT&CK techniques: Application Layer Protocol (T1071) Non-Standard Port (T1571)
    Required data: XDR Agent
    Attacker's goals: Attackers might use TOR IP combined with random ports.to hide C2 inbound communication from inside a host.
    Investigative actions: Investigate the network configuration related to the participating port. Investigate processes that were listening to that port.

    Variations

    Abnormal network communication through TOR using an uncommon port and App-id

    Low overridden

    Suspicious connection from a known TOR IP to an uncommon port and App-id. overridden

    Abnormal network communication through TOR using a suspicious port

    Low overridden

    Suspicious connection from a known TOR IP to an uncommon potential C2 communication port. overridden