Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. tactic: TA0007 ✕
Download CSV Show ATT&CK heatmapPossible path traversal via HTTP request Low 3 variations
The endpoint received a suspicious URI via an HTTP request that resembles a path traversal attempt.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 2 Days
ATT&CK tactics: Discovery (TA0007)ATT&CK techniques: File and Directory Discovery (T1083)Required data: Palo Alto Networks Firewall EAL Logs XDR AgentDetector tags: Webshell AnalyticsAttacker's goals: Attackers may exploit server components or misconfigurations to access arbitrary sensitive files on the web server.Investigative actions: Inspect the legitimacy of the URI path. Ensure that the rare URI is not a legitimate result of routine development actions on the web server.Variations
Possible sensitive path traversal via HTTP request
Medium overridden
The endpoint received a suspicious URI via an HTTP request that resembles a path traversal attempt. overridden
Possible path traversal via HTTP request from a TOR exit node
Medium overridden
The endpoint received a suspicious URI via an HTTP request that resembles a path traversal attempt. overridden
Possible credential path traversal via HTTP request
Medium overridden
The endpoint received a suspicious URI via an HTTP request that resembles a path traversal attempt. overridden