Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters.
Download CSV Show ATT&CK heatmapMassive upload to a rare storage or mail domain Informational Identity Threat Module, SaaS Threat Detection 1 variation
A large amount of data was transferred to an external site that is used for mail or storage. This behavior may indicate data exfiltration.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- 1 Hour
- Deduplication:
- 1 Day
ATT&CK tactics: Exfiltration (TA0010)ATT&CK techniques: Exfiltration Over Web Service (T1567) Exfiltration Over Web Service: Exfiltration to Cloud Storage (T1567.002)Required data: Palo Alto Networks Firewall EAL Logs Palo Alto Networks Firewall threat Logs XDR AgentDetector tags: Data Detection & ResponseAttacker's goals: A user uploaded an abnormal amount of data to a file sharing service. This activity might indicate an attempt to exfiltrate files and data from the organization.Investigative actions: Check for any other suspicious activity related to the host and the user involved in the alert. Identify the user uploading the data to determine if the transfer is sanctioned.Variations
A user uploaded over 500 MB to a rare storage or mail domain
Low overridden
A user uploaded over 500 MB to a file sharing service that is rarely accessed by them or anyone else in the organization. overridden