Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters.

Download CSV Show ATT&CK heatmap
  • Massive upload to a rare storage or mail domain Informational Identity Threat Module, SaaS Threat Detection 1 variation

    A large amount of data was transferred to an external site that is used for mail or storage. This behavior may indicate data exfiltration.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    1 Hour
    Deduplication:
    1 Day
    ATT&CK tactics: Exfiltration (TA0010)
    ATT&CK techniques: Exfiltration Over Web Service (T1567) Exfiltration Over Web Service: Exfiltration to Cloud Storage (T1567.002)
    Required data: Palo Alto Networks Firewall EAL Logs Palo Alto Networks Firewall threat Logs XDR Agent
    Detector tags: Data Detection & Response
    Attacker's goals: A user uploaded an abnormal amount of data to a file sharing service. This activity might indicate an attempt to exfiltrate files and data from the organization.
    Investigative actions: Check for any other suspicious activity related to the host and the user involved in the alert. Identify the user uploading the data to determine if the transfer is sanctioned.

    Variations

    A user uploaded over 500 MB to a rare storage or mail domain

    Low overridden

    A user uploaded over 500 MB to a file sharing service that is rarely accessed by them or anyone else in the organization. overridden