Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source
  • Successful universal authentication with suspicious features Informational Identity Analytics 4 variations

    A universal authentication was flagged as suspicious based on anomalous features.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Initial Access (TA0001)
    ATT&CK techniques: Valid Accounts (T1078)
    Attacker's goals: Use an account that was possibly compromised to gain access to the network, while potentially using an anonymizing service to obfuscate their origin.
    Investigative actions: Investigate the suspicious authentication. Verify if the ASN is an approved ASN to authenticate from. Follow further actions done by the user. If the IP is associated with a tunnel operator, check whether it is an approved VPN.

    Variations

    Successful universal authentication sign-in from a TOR exit node

    Medium overridden

    A successful sign-in from a TOR exit node in universal authentication. overridden

    Successful universal authentication from a suspicious tunnel operator

    Low overridden

    A successful universal authentication was made through a suspicious or rarely seen tunnel operator. overridden

    Suspicious successful universal authentication from ASN

    Informational overridden

    A successful universal authentication was made from a suspicious or previously unseen ASN. overridden

    Successful universal authentication from a new country in organization

    Informational overridden

    A user authenticated in universal authentication from an unusual country that no one from this organization has connected from before in universal authentication. This may indicate the account was compromised. overridden