Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters.
Download CSV Show ATT&CK heatmapSuspicious SaaS API call from a Tor exit node High Identity Threat Module, SaaS Threat Detection 2 variations
A SaaS API was called from a Tor exit node.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Command and Control (TA0011)ATT&CK techniques: Proxy: Multi-hop Proxy (T1090.003)Required data: Box Audit Log DropBox Google Workspace Audit Logs Office 365 AuditAttacker's goals: Conceal information about malicious activities, such as location and network usage.Investigative actions: Block all web traffic to and from public Tor entry and exit nodes.Variations
A Failed API call from a Tor exit node
Informational overridden
A SaaS API was called from a Tor exit node. overridden
Suspicious SaaS API call from a Tor exit node via Mobile Device
Medium overridden
A SaaS API was called from a Tor exit node. overridden