Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. tactic: TA0011 ✕ technique: T1572 ✕
Download CSV Show ATT&CK heatmapUnusual SSH Activity Informational 2 variations
Unusual SSH activity was detected that involved a higher than usual volume of data transfer and an abnormally long session.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- 2 Hours
- Deduplication:
- 1 Day
ATT&CK tactics: Command and Control (TA0011)ATT&CK techniques: Protocol Tunneling (T1572)Required data: Palo Alto Networks Firewall traffic Logs XDR AgentAttacker's goals: Attackers may use SSH or any similar utility to create a network tunnel to allow an attacker to covertly connect to an internal host.Investigative actions: Review the client IP/Agent for using known intelligence tools. Investigate the user accounts involved in the SSH connections to determine if credentials were compromised, Additionally examine logs for any unexpected data transfers or commands that may indicate malicious intent.Variations
Unusual, long SSH activity with tunnel characteristics
Low overridden
Unusual SSH activity was detected that involved a high volume of data transfer and abnormal session duration. overridden
Unusual SSH activity with tunnel characteristics to external destination
Low overridden
Unusual SSH activity was detected that involved a higher than usual volume of data transfer and an abnormally long session. overridden