Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters. tactic: TA0011 ✕

Download CSV Show ATT&CK heatmap
  • Non-browser access to a pastebin-like site Low 4 variations

    Non-browser access to a pastebin-like site.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Command and Control (TA0011)
    ATT&CK techniques: Web Service (T1102)
    Required data: Palo Alto Networks Url Logs
    Attacker's goals: Data exfiltration or attack tool staging.
    Investigative actions: Examine the host to verify that the host was not part of infiltration or data exfiltration from the organization. Verify that the host doesn't have sensitive company data that can be easily exfiltrated.

    Variations

    Non-browser or an uncommon browser access to a pastebin-like site

    Informational overridden

    Non-browser or an uncommon browser access to a pastebin-like site. overridden

    Non-browser access to google sheets API

    Low overridden

    Non-browser access to google sheets API. overridden

    Non-browser failed access to a pastebin-like site

    Low overridden

    Non-browser failed access to a pastebin-like site. overridden

    Rare non-browser access to a pastebin-like site

    Medium overridden

    Rare non-browser access to a pastebin-like site. overridden