Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters. technique: T1071 ✕

Download CSV Show ATT&CK heatmap
  • Rare AppID usage to a rare destination Informational 2 variations

    Rare AppID with port usage to rare destination.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    14 Days
    ATT&CK tactics: Command and Control (TA0011)
    ATT&CK techniques: Application Layer Protocol (T1071) Non-Standard Port (T1571)
    Required data: Palo Alto Networks Firewall traffic Logs XDR Agent Third-Party Firewalls
    Attacker's goals: Attackers might use well-known ports with uncommon applications to avoid being detected by a non-application aware firewall or to bypass firewall rules based only on ports.
    Investigative actions: Investigate the endpoints participating in the session.

    Variations

    Rare AppID usage to a rare destination using an unsigned process

    Low overridden

    Rare AppID with port usage to rare destination. overridden

    Rare AppID usage to a rare destination from an internet-facing server

    Low overridden

    Rare AppID with port usage to rare destination. overridden