Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. technique: T1078 ✕
Download CSV Show ATT&CK heatmapVPN login by a service account Low Identity Analytics 1 variation
A service account attempted to log in to a VPN service.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Initial Access (TA0001)ATT&CK techniques: Valid Accounts: Domain Accounts (T1078.002)Required data: Palo Alto Networks Global Protect Third-Party VPNsAttacker's goals: Use an account that was possibly compromised in the past to gain access to the network and access privileged resources.Investigative actions: See whether the service authentication was successful. Check whether the account has done any administrative actions it should not usually do. Look for more logins and authentications by the account throughout the network.Variations
Rare VPN login by an administrative service account
Medium overridden
An administrative service account attempted to log in to a VPN service. overridden