Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters.

Download CSV Show ATT&CK heatmap
  • Multiple alerts associated with a single RDP connection Informational 4 variations

    Multiple alerts associated with a single RDP connection were triggered.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    3 Hours
    Deduplication:
    1 Day
    ATT&CK tactics: Lateral Movement (TA0008)
    ATT&CK techniques: Remote Services: Remote Desktop Protocol (T1021.001)
    Required data: Palo Alto Networks Platform Alerts Third-Party Alerts
    Detector tags: Enhanced RDP Analytics
    Attacker's goals: Adversaries may use RDP for initial access or lateral movement within a network.
    Investigative actions: Investigate the source and destination of the RDP communication. Check if this communication is legitimate and expected. Analyze the user and process that initiated the RDP connection.

    Variations

    Multiple elevated severity alerts associated with a single RDP connection

    Medium overridden

    RDP-related alerts include at least one medium or higher severity alert. overridden

    Multiple alerts associated with a single RDP connection - high risk-processes

    Low overridden

    RDP-related alerts involve high-risk processes (service management, offensive tools, or script execution). overridden

    Diverse alerts associated with a single RDP connection

    Low overridden

    RDP-related alerts show diverse post-connection activity across multiple attack stages. overridden

    Pre-connection activity alongside abnormal RDP connection

    Low overridden

    Suspicious activity was detected before an abnormal RDP session was established. overridden