Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters. tactic: TA0043 ✕

Download CSV Show ATT&CK heatmap
  • Subdomain Fuzzing Low 1 variation

    The root domain within the network is experiencing an unusually high number of access requests to its subdomains, significantly exceeding the typical activity levels for that domain. This anomaly could suggest that someone is attempting to enumerate subdomains or uncover additional virtual hosts associated with the domain, possibly as part of a reconnaissance effort to identify vulnerable or less-secured entry points into the network.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    20 Minutes
    Deduplication:
    1 Day
    ATT&CK tactics: Reconnaissance (TA0043)
    ATT&CK techniques: Active Scanning: Wordlist Scanning (T1595.003)
    Required data: Palo Alto Networks Firewall EAL Logs XDR Agent
    Attacker's goals: Scan a known external facing asset to gain knowledge about the organization.
    Investigative actions: Verify that the domain doesn't host numerous subdomains. Verify that the source of the scan is not a known external scanner.

    Variations

    Subdomain Fuzzing To a Rare Destination

    Medium overridden

    The root domain within the network is experiencing an unusually high number of access requests to its subdomains, significantly exceeding the typical activity levels for that domain. This anomaly could suggest that someone is attempting to enumerate subdomains or uncover additional virtual hosts associated with the domain, possibly as part of a reconnaissance effort to identify vulnerable or less-secured entry points into the network. overridden