Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source
  • Rare NTLM Usage by User Informational Identity Analytics

    Rare authentication by user account to host via NTLM. The user has not authenticated with NTLM in the past 30 days. This may be indicative of downgrade attacks from Kerberos to NTLM.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Lateral Movement (TA0008)
    ATT&CK techniques: Use Alternate Authentication Material (T1550)
    Required data: Palo Alto Networks Firewall EAL Logs XDR Agent
    Attacker's goals: The attacker is attempting to move laterally within a compromised network.
    Investigative actions: Verify any successful authentication for the user account referenced by the alert, as these can indicate the attacker managed to use the stolen credentials.