Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters.
Download CSV Show ATT&CK heatmapLarge Upload (SMTP) Low 1 variation
The endpoint, which is not an internal SMTP server, emailed an excessive amount of data from your network.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- 1 Day
- Deduplication:
- 1 Day
ATT&CK tactics: Exfiltration (TA0010)ATT&CK techniques: Exfiltration Over Alternative Protocol (T1048)Required data: Palo Alto Networks Firewall traffic Logs XDR Agent Third-Party FirewallsAttacker's goals: Transfer data they have stolen from your network to a location that is convenient and useful to him.Investigative actions: Identify the process/user performing the data transfer to determine if the transfer is sanctioned. Verify that the source is not a mail server. Check if the target address represents a mail service that rarely used in the organization. If so, this might indicate on file exfiltration attempt.Variations
Large Upload (SMTP)
Informational overridden
The endpoint, which is not an internal SMTP server, emailed an excessive amount of data from your network. overridden