Analytics Alerts
Browse the Cortex analytics alert reference.
2 alerts match the current filters. technique: T1078 ✕
Download CSV Show ATT&CK heatmapLogin by a dormant user Informational Identity Analytics 1 variation
A dormant user logged on after having been unused for a month or longer. This may indicate the account is misused by an attacker.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Stealth (TA0005)ATT&CK techniques: Valid Accounts: Domain Accounts (T1078.002)Required data: XDR AgentAttacker's goals: Use a compromised user account that has not been used for a long time and is therefore less likely to be noticed.Investigative actions: Confirm that the activity is benign (e.g. the user returned from a long leave of absence). See whether there are other abnormal actions done by the user (e.g. files\commands\other logins). Check whether you have issues with your Cloud Identity Engine failing to sync data from Active Directory.Variations
Cached interactive login by a dormant user
Informational overridden
A dormant user logged on after having been unused for a month or longer. This may indicate the account is misused by an attacker. overridden
VPN login by a dormant user Informational Identity Analytics
A dormant user logged on to a VPN service after having been unused for a month or longer. This may indicate the account is misused by an attacker.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Stealth (TA0005)ATT&CK techniques: Valid Accounts: Domain Accounts (T1078.002)Required data: Palo Alto Networks Global Protect Third-Party VPNsAttacker's goals: Use a compromised user account which has not been used for a long while, and therefore is less likely to be noticed.Investigative actions: Confirm that the activity is benign (e.g. the user returned from a long leave of absence). See whether there are other abnormal actions done by the user (e.g. files\commands\other logins). Check if the user initiated other logins aside from a VPN login. Check whether you have issues with your Cloud Identity Engine failing to sync data from Active Directory.