Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters. technique: T1048 ✕

Download CSV Show ATT&CK heatmap
  • Large Upload (SMTP) Low 1 variation

    The endpoint, which is not an internal SMTP server, emailed an excessive amount of data from your network.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    1 Day
    Deduplication:
    1 Day
    ATT&CK tactics: Exfiltration (TA0010)
    ATT&CK techniques: Exfiltration Over Alternative Protocol (T1048)
    Required data: Palo Alto Networks Firewall traffic Logs XDR Agent Third-Party Firewalls
    Attacker's goals: Transfer data they have stolen from your network to a location that is convenient and useful to him.
    Investigative actions: Identify the process/user performing the data transfer to determine if the transfer is sanctioned. Verify that the source is not a mail server. Check if the target address represents a mail service that rarely used in the organization. If so, this might indicate on file exfiltration attempt.

    Variations

    Large Upload (SMTP)

    Informational overridden

    The endpoint, which is not an internal SMTP server, emailed an excessive amount of data from your network. overridden