Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters.

Download CSV Show ATT&CK heatmap
  • Uncommon reverse SSH tunnel to external domain/ip Low 3 variations

    An uncommon reverse SSH tunnel might have been created.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Command and Control (TA0011)
    ATT&CK techniques: Protocol Tunneling (T1572)
    Required data: XDR Agent
    Detector tags: Abnormal Communication Analytics
    Attacker's goals: Attackers may use SSH to create an encrypted tunnel to allow an attacker to covertly connect to an internal host.
    Investigative actions: Review the external ip/domain. Investigate the causality of the process.

    Variations

    Uncommon reverse SOCKS proxy SSH tunnel to external domain/ip

    Medium overridden

    An uncommon reverse SSH tunnel might have been created. overridden

    Uncommon reverse SSH tunnel to external domain/ip to a sensitive port via a non-default bind port

    Medium overridden

    An uncommon reverse SSH tunnel might have been created. overridden

    Uncommon reverse SSH tunnel to external domain/ip using a sensitive port

    Low overridden

    An uncommon reverse SSH tunnel might have been created. overridden