Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

2 alerts match the current filters.

Download CSV Show ATT&CK heatmap
  • Abnormal sensitive RPC traffic to multiple hosts Low 1 variation

    The endpoint performed unfamiliar RPC activity to multiple hosts using a known sensitive interface.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    5 Hours
    Deduplication:
    1 Day
    ATT&CK tactics: Lateral Movement (TA0008)
    ATT&CK techniques: Remote Services (T1021)
    Required data: Palo Alto Networks Firewall EAL Logs XDR Agent with eXtended Threat Hunting (XTH)
    Detector tags: NDR Lateral Movement Analytics
    Attacker's goals: An adversary may enumerate different protocols to gain information and plan its lateral movement over the network.
    Investigative actions: Check if the host is a newly deployed server that provides RPC based services to multiple hosts. Verify the legitimacy of the actor process (and its causality) that initiated this RPC traffic.

    Variations

    Abnormal sensitive RPC traffic to multiple IPs

    Informational overridden

    The endpoint performed unfamiliar RPC activity to multiple hosts using a known sensitive interface. overridden

  • Abnormal sensitive RPC traffic to multiple hosts from a rarely seen host Low

    The endpoint performed unfamiliar RPC activity to multiple hosts using a known sensitive interface.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    5 Hours
    Deduplication:
    1 Day
    ATT&CK tactics: Lateral Movement (TA0008)
    ATT&CK techniques: Remote Services (T1021)
    Required data: Palo Alto Networks Firewall EAL Logs XDR Agent with eXtended Threat Hunting (XTH)
    Detector tags: NDR Lateral Movement Analytics, NDR Unmanaged Subnet Analytics
    Attacker's goals: An adversary may enumerate different protocols to gain information and plan its lateral movement over the network.
    Investigative actions: Check if the host is a newly deployed server that provides RPC based services to multiple hosts. Verify the legitimacy of the actor process (and its causality) that initiated this RPC traffic.