Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source
  • Rare connection to external IP address or host by an application using RMI-IIOP or LDAP protocol Informational 4 variations

    A process made a connection to an external IP address or host that is rarely connected to by the organization.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Command and Control (TA0011)
    ATT&CK techniques: Application Layer Protocol (T1071)
    Required data: Palo Alto Networks Url Logs
    Attacker's goals: Connect to a server to retrieve commands or exfiltrate data.
    Investigative actions: Check whether the process was injected or otherwise subverted for malicious use.

    Variations

    Rare connection to external IP address or host by a java application using LDAP protocol

    Medium overridden

    A Java Process that never created LDAP connection before connected to an external IP address or host, which is rarely connected to from the organization using LDAP protocol. overridden

    Rare connection to external IP address or host by a java application using LDAP protocol

    Medium overridden

    A Java Process that never created RMI-IIOP connection before connected to an external IP address or host, which is rarely connected to from the organization using LDAP protocol. overridden

    Rare connection to external IP address or host by a java application using LDAP protocol

    Low overridden

    A Java Process connected to an external IP address or host, which is rarely connected to from the organization using LDAP protocol. overridden

    Rare connection to external IP address or host by a java application using RMI-IIOP protocol

    Low overridden

    A Java Process connected to an external IP address or host, which is rarely connected to from the organization using RMI-IIOP protocol. overridden