Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. tactic: TA0011 ✕ technique: T1071 ✕
Download CSV Show ATT&CK heatmapRare process created an SSH session to an uncommon external host Low 3 variations
Rare process created an SSH session to an uncommon external host.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Command and Control (TA0011)ATT&CK techniques: Application Layer Protocol (T1071)Required data: Palo Alto Networks Firewall traffic Logs XDR Agent Third-Party FirewallsDetector tags: EDR Windows C2 AnalyticsAttacker's goals: Attackers may use SSH or any similar utility to as a Command and Control (C2) channel or to exfiltrate data to a remote host.Investigative actions: Investigate the actor process and its causality. Review the external IP/domain using known intelligence tools. Search for processes or files that were accessed by this SSH instance.Variations
Rare process created an SSH session to a domain with an uncommon TLD
Medium overridden
Rare process created an SSH session to a domain with an uncommon TLD. overridden
Rare process created an SSH session to an globally uncommon external host
Low overridden
Rare process created an SSH session to an globally uncommon external host. overridden
Rare process created an SSH session to an external host
Informational overridden
Rare process created an SSH session to an external host. overridden