Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters. tactic: TA0007 ✕

Download CSV Show ATT&CK heatmap
  • Possible path traversal via HTTP request Low 3 variations

    The endpoint received a suspicious URI via an HTTP request that resembles a path traversal attempt.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    2 Days
    ATT&CK tactics: Discovery (TA0007)
    ATT&CK techniques: File and Directory Discovery (T1083)
    Required data: Palo Alto Networks Firewall EAL Logs XDR Agent
    Detector tags: Webshell Analytics
    Attacker's goals: Attackers may exploit server components or misconfigurations to access arbitrary sensitive files on the web server.
    Investigative actions: Inspect the legitimacy of the URI path. Ensure that the rare URI is not a legitimate result of routine development actions on the web server.

    Variations

    Possible sensitive path traversal via HTTP request

    Medium overridden

    The endpoint received a suspicious URI via an HTTP request that resembles a path traversal attempt. overridden

    Possible path traversal via HTTP request from a TOR exit node

    Medium overridden

    The endpoint received a suspicious URI via an HTTP request that resembles a path traversal attempt. overridden

    Possible credential path traversal via HTTP request

    Medium overridden

    The endpoint received a suspicious URI via an HTTP request that resembles a path traversal attempt. overridden