Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters. tactic: TA0112 ✕

Download CSV Show ATT&CK heatmap
  • Suspicious SSH Downgrade Low 2 variations

    The endpoint asked for an ssh downgrade, ssh downgrade may enable attackers to perform attacks such as data decryption, man in the middle, session hijack, replay attack and more.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Lateral Movement (TA0008) Defense Impairment (TA0112)
    ATT&CK techniques: Remote Services (T1021) Downgrade Attack (T1689)
    Required data: Palo Alto Networks Firewall EAL Logs
    Detector tags: NDR Lateral Movement Analytics
    Attacker's goals: Attackers may attempt to move laterally over the network by exploiting problems in a lower version of SSH.
    Investigative actions: Audit the authentication attempts in the SSH server from the alerted host. If the source host authenticated to the SSH server, it may indicate that the attacker managed to connect to the remote host maliciously.

    Variations

    A Host Performed an SSH Downgrade For The First Time In The Last 30 Days

    Low overridden

    The endpoint asked for an ssh downgrade, ssh downgrade may enable attackers to perform attacks such as data decryption, man in the middle, session hijack, replay attack and more. With a lower version than the source host used in the past. overridden

    A Target Server Performed an SSH Downgrade For The First Time In The Last 30 Days

    Low overridden

    The endpoint asked for an ssh downgrade, ssh downgrade may enable attackers to perform attacks such as data decryption, man in the middle, session hijack, replay attack and more. With a lower version than the remote host used in the past. overridden