Analytics Informational

AI-determined combination of risky alerts under the same actor process

Multiple alerts likely to be associated with an incident were identified under the same actor process.

Module:
Platform Analytics
Data source:
Palo Alto Networks Platform Alerts, Third-Party Alerts
ATT&CK tactics: Execution (TA0002)
ATT&CK techniques: User Execution (T1204) Native API (T1106)
Detector tags: AI Insight Fusion Analytics
Attacker's goals:

Perform multiple activities to achieve the attacker's goals in the target environment.

Investigative actions:

Investigate the actor process of these alerts. Track down other suspicious activity under this actor process.

Test period:
12 Hours
Deduplication:
1 Day
1 variation:
  • AI-determined combination of risky alerts under the same actor process: LDAP traffic from non-standard process with SMB traffic from non-standard process Medium (parent: Informational)