Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source
  • VPN access with an abnormal operating system Informational Identity Analytics 2 variations

    A user accessed a VPN with an abnormal operating system.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Initial Access (TA0001)
    ATT&CK techniques: Valid Accounts: Domain Accounts (T1078.002)
    Required data: Palo Alto Networks Global Protect Third-Party VPNs
    Attacker's goals: Use a legitimate user and connect to a VPN service to gain access to the network.
    Investigative actions: See whether the service authentication was successful. Confirm that the activity is benign (e.g. the user has really moved to a new operating system). Follow actions and suspicious activities regarding the user.

    Variations

    VPN access with a suspicious operating system

    Medium overridden

    A user accessed a VPN with an abnormal operating system. overridden

    VPN access from an abnormal operating system with suspicious characteristics

    Low overridden

    A user accessed a VPN from an abnormal operating system with some more suspicious characteristics that flagged this login attempt as a suspicious login. overridden