Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source
  • First VPN access from ASN for user Informational Identity Analytics 1 variation

    A user logged in to a VPN with a new ASN.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Initial Access (TA0001)
    ATT&CK techniques: Valid Accounts: Domain Accounts (T1078.002)
    Required data: Palo Alto Networks Global Protect Third-Party VPNs
    Attacker's goals: Use an account that was possibly compromised to gain access to the network.
    Investigative actions: Confirm that the activity is benign (e.g. the user has switched locations and providers). Verify if the ASN is an approved ASN to authenticate from. Follow further actions done by the user.

    Variations

    Unusual VPN access from ASN

    Low overridden

    An unusual VPN login was made by a user. overridden