Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters.

Download CSV Show ATT&CK heatmap
  • Uncommon network tunnel creation Informational 3 variations

    An uncommon network tunnel was established.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    12 Hours
    ATT&CK tactics: Command and Control (TA0011)
    ATT&CK techniques: Protocol Tunneling (T1572)
    Required data: Palo Alto Networks Url Logs
    Attacker's goals: Attackers may use SSH or any similar utility to create a network tunnel to allow an attacker to covertly connect to an internal host.
    Investigative actions: Review the external IP/domain using known intelligence tools. Investigate the causality of the process and its user ID to find uncommon behaviors. Search for processes or files that were created by this SSH instance.

    Variations

    Uncommon network tunnel creation

    Informational overridden

    An uncommon network tunnel was established using ACS_ssh.exe. overridden

    Uncommon SSH tunnel to unpopular IP address

    Low overridden

    An uncommon SSH tunnel was established to an unpopular remote IP address at the organization. overridden

    An uncommon network tunnel was established over the default SSH port

    Low overridden

    An unpopular process and command line created a network tunnel over the default SSH port. overridden