Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. technique: T1550 ✕
Download CSV Show ATT&CK heatmapSuspicious Encrypting File System Remote call (EFSRPC) to domain controller Medium
An Encrypting File System Remote call (EFSRPC) was made to a domain controller.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Lateral Movement (TA0008)ATT&CK techniques: Use Alternate Authentication Material: Pass the Hash (T1550.002)Required data: Palo Alto Networks Firewall EAL Logs XDR Agent with eXtended Threat Hunting (XTH)Attacker's goals: An attacker is attempting to steal credentials and move laterally within a network.Investigative actions: Check for suspicious processes on the host. Check if the source host is a vulnerability scanner. Look for following suspicious connections using the DC machine account.