Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

2 alerts match the current filters.

Download CSV Show ATT&CK heatmap
  • Unusual SSH Activity Informational 2 variations

    Unusual SSH activity was detected that involved a higher than usual volume of data transfer and an abnormally long session.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    2 Hours
    Deduplication:
    1 Day
    ATT&CK tactics: Command and Control (TA0011)
    ATT&CK techniques: Protocol Tunneling (T1572)
    Required data: Palo Alto Networks Firewall traffic Logs XDR Agent
    Attacker's goals: Attackers may use SSH or any similar utility to create a network tunnel to allow an attacker to covertly connect to an internal host.
    Investigative actions: Review the client IP/Agent for using known intelligence tools. Investigate the user accounts involved in the SSH connections to determine if credentials were compromised, Additionally examine logs for any unexpected data transfers or commands that may indicate malicious intent.

    Variations

    Unusual, long SSH activity with tunnel characteristics

    Low overridden

    Unusual SSH activity was detected that involved a high volume of data transfer and abnormal session duration. overridden

    Unusual SSH activity with tunnel characteristics to external destination

    Low overridden

    Unusual SSH activity was detected that involved a higher than usual volume of data transfer and an abnormally long session. overridden

  • Unusual SSH activity that resembles SSH proxy Informational 3 variations

    A host initiated and received an unusual SSH connection, which is consistent with being an SSH proxy. This behavior may indicate an attempt to establish covert command and control communication or to exfiltrate data.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Command and Control (TA0011)
    ATT&CK techniques: Proxy: Internal Proxy (T1090.001)
    Required data: Palo Alto Networks Firewall traffic Logs XDR Agent
    Attacker's goals: Attackers aim to establish a covert command and control channel or relay communications through a compromised SSH connection.
    Investigative actions: Review the SSH connections to identify any unusual proxy activity or traffic patterns. Investigate the user accounts involved in the SSH connections to determine if credentials were compromised. Additionally, examine logs for any unexpected data transfers or commands that may indicate malicious intent.

    Variations

    High Volume Unusual SSH activity that resembles SSH proxy

    Low overridden

    A host initiated and received an unusual SSH connection, which is consistent with being an SSH proxy. This behavior may indicate an attempt to establish covert command and control communication or to exfiltrate data. overridden

    Suspicious SSH activity that resembles SSH proxy

    Low overridden

    A host initiated and received an unusual SSH connection, which is consistent with being an SSH proxy. This behavior may indicate an attempt to establish covert command and control communication or to exfiltrate data. overridden

    Unusual SSH activity that resembles SSH proxy detected

    Low overridden

    A host initiated and received an unusual SSH connection, which is consistent with being an SSH proxy. This behavior may indicate an attempt to establish covert command and control communication or to exfiltrate data. overridden