Analytics BIOC Informational

A user accessed an uncommon AppID

A user accessed an uncommon AppID that is rarely accessed by them or anyone else in the organization.

Module:
Identity Threat Detection (ITDR)
Licensed by:
Identity Threat Detection (ITDR)
Data source:
Palo Alto Networks Firewall EAL Logs, Palo Alto Networks Firewall threat Logs, Palo Alto Networks Firewall traffic Logs, XDR Agent
ATT&CK tactics: Exfiltration (TA0010)
ATT&CK techniques: Exfiltration Over Web Service (T1567)
Attacker's goals:

A user accessed an uncommon AppID that is rarely accessed by them or anyone else in the organization. This may indicate an attempt to exfiltrate sensitive data.

Investigative actions:

Check for any other suspicious activity related to the host and the user involved in the alert.

Test period:
N/A (single event)
Deduplication:
1 Day
5 variations:
  • A user accessed an uncommon external peer-to-peer service Informational
  • A user accessed an uncommon external file-sharing service Informational
  • A user accessed an uncommon peer-to-peer service Informational
  • A user accessed an uncommon file-sharing service Informational
  • A user accessed an uncommon VPN service Informational