Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. technique: T1021 ✕
Download CSV Show ATT&CK heatmapMultiple alerts associated with a single RDP connection Informational 4 variations
Multiple alerts associated with a single RDP connection were triggered.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- 3 Hours
- Deduplication:
- 1 Day
ATT&CK tactics: Lateral Movement (TA0008)ATT&CK techniques: Remote Services: Remote Desktop Protocol (T1021.001)Required data: Palo Alto Networks Platform Alerts Third-Party AlertsDetector tags: Enhanced RDP AnalyticsAttacker's goals: Adversaries may use RDP for initial access or lateral movement within a network.Investigative actions: Investigate the source and destination of the RDP communication. Check if this communication is legitimate and expected. Analyze the user and process that initiated the RDP connection.Variations
Multiple elevated severity alerts associated with a single RDP connection
Medium overridden
RDP-related alerts include at least one medium or higher severity alert. overridden
Multiple alerts associated with a single RDP connection - high risk-processes
Low overridden
RDP-related alerts involve high-risk processes (service management, offensive tools, or script execution). overridden
Diverse alerts associated with a single RDP connection
Low overridden
RDP-related alerts show diverse post-connection activity across multiple attack stages. overridden
Pre-connection activity alongside abnormal RDP connection
Low overridden
Suspicious activity was detected before an abnormal RDP session was established. overridden