Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. technique: T1078 ✕
Download CSV Show ATT&CK heatmapVPN access with an abnormal operating system Informational Identity Analytics 2 variations
A user accessed a VPN with an abnormal operating system.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Initial Access (TA0001)ATT&CK techniques: Valid Accounts: Domain Accounts (T1078.002)Required data: Palo Alto Networks Global Protect Third-Party VPNsAttacker's goals: Use a legitimate user and connect to a VPN service to gain access to the network.Investigative actions: See whether the service authentication was successful. Confirm that the activity is benign (e.g. the user has really moved to a new operating system). Follow actions and suspicious activities regarding the user.Variations
VPN access with a suspicious operating system
Medium overridden
A user accessed a VPN with an abnormal operating system. overridden
VPN access from an abnormal operating system with suspicious characteristics
Low overridden
A user accessed a VPN from an abnormal operating system with some more suspicious characteristics that flagged this login attempt as a suspicious login. overridden