Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters. technique: T1557 ✕

Download CSV Show ATT&CK heatmap
  • Uncommon WPAD queries Informational 3 variations

    There were multiple attempts to access WPAD resources by a single host in your network. This may indicate a malicious activity.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    1 Hour
    Deduplication:
    1 Day
    ATT&CK tactics: Credential Access (TA0006)
    ATT&CK techniques: Adversary-in-the-Middle (T1557)
    Required data: Palo Alto Networks Firewall EAL Logs XDR Agent
    Attacker's goals: Attackers may attempt to move laterally over the network by exploiting problems in WPAD.
    Investigative actions: Verify that the source host is legitimate.* Examine the legitimacy of the application that produced this uncommon WPAD. Examine the parent process of this application.

    Variations

    Uncommon WPAD queries to a external domain

    Informational overridden

    There were multiple attempts to access WPAD resources by a single host in your network. This may indicate a malicious activity. overridden

    Suspicious WPAD queries

    Low overridden

    There were multiple attempts to access WPAD resources by a single host in your network. This may indicate a malicious activity. overridden

    Uncommon WPAD queries using an uncommon port

    Informational overridden

    There were multiple attempts to access WPAD resources by a single host in your network. This may indicate a malicious activity. overridden