Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters.

Download CSV Show ATT&CK heatmap
  • Rare process created an SSH session to an uncommon external host Low 3 variations

    Rare process created an SSH session to an uncommon external host.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Command and Control (TA0011)
    ATT&CK techniques: Application Layer Protocol (T1071)
    Required data: Palo Alto Networks Firewall traffic Logs XDR Agent Third-Party Firewalls
    Detector tags: EDR Windows C2 Analytics
    Attacker's goals: Attackers may use SSH or any similar utility to as a Command and Control (C2) channel or to exfiltrate data to a remote host.
    Investigative actions: Investigate the actor process and its causality. Review the external IP/domain using known intelligence tools. Search for processes or files that were accessed by this SSH instance.

    Variations

    Rare process created an SSH session to a domain with an uncommon TLD

    Medium overridden

    Rare process created an SSH session to a domain with an uncommon TLD. overridden

    Rare process created an SSH session to an globally uncommon external host

    Low overridden

    Rare process created an SSH session to an globally uncommon external host. overridden

    Rare process created an SSH session to an external host

    Informational overridden

    Rare process created an SSH session to an external host. overridden