Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source
  • Impossible traveler - VPN Low Identity Analytics 3 variations

    A user connected to a VPN service from multiple remote countries in a short period of time, which should normally be impossible. This may indicate the account is compromised.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    3 Hours
    Deduplication:
    7 Days
    ATT&CK tactics: Credential Access (TA0006) Resource Development (TA0042)
    ATT&CK techniques: Compromise Accounts (T1586) Brute Force: Password Guessing (T1110.001)
    Required data: Palo Alto Networks Global Protect Third-Party VPNs
    Attacker's goals: Gain user-account credentials.
    Investigative actions: Check if the user routed their traffic via a proxy, or shared their credentials with a remote employee.

    Variations

    Possible Impossible traveler via VPN

    Informational overridden

    A user connected to a VPN service from multiple remote countries in a short period of time, which should normally be impossible. This may indicate the account is compromised. overridden

    VPN impossible traveler from a VPN or proxy

    Informational overridden

    A user connected to a VPN service from multiple remote countries in a short period of time, which should normally be impossible. This may indicate the account is compromised. overridden

    VPN impossible traveler with an unusual parameter

    Medium overridden

    A user connected to a VPN service from multiple remote countries in a short period of time, which should normally be impossible. This may indicate the account is compromised. overridden