Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters.
Download CSV Show ATT&CK heatmapAnalytics enhanced NGFW Threat Alert - Rare Internal Firewall Vulnerability Threat Alert Informational 1 variation
An internal host triggered an NGFW (Next-Generation Firewall) vulnerability threat alert targeting another internal host. This activity is highly anomalous as it deviates from the source host's historical behavior and is rarely seen targeting this specific destination across the organization.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Reconnaissance (TA0043)ATT&CK techniques: Active Scanning: Vulnerability Scanning (T1595.002)Required data: Palo Alto Networks Firewall threat Logs XDR AgentAttacker's goals: Adversaries may attempt to exploit a vulnerability to gain initial access, execute malicious code, or move laterally within the internal network.Investigative actions: Verify the firewall alert details, including the threat name, CVE, and severity. Inspect the destination internal host for signs of successful exploitation, such as suspicious processes, new files, or unusual outbound connections. Determine if the source host is an internal scanner or a compromised asset. Review recent changes or updates on the target system that might have exposed the vulnerability. Check if the traffic was blocked by the firewall or only detected.Variations
Analytics enhanced NGFW Threat Alert - Rare Internal Firewall Vulnerability Threat Alert Categorized as code-execution/info-leak
Informational overridden
An internal host triggered an NGFW (Next-Generation Firewall) vulnerability threat alert targeting another internal host. This activity is highly anomalous as it deviates from the source host's historical behavior and is rarely seen targeting this specific destination across the organization. overridden