Analytics
Informational
✕
AI-determined combination of risky alerts under the same causality
Multiple alerts likely to be associated with an incident were identified under the same causality.
- Module:
- Platform Analytics
- Data source:
- Palo Alto Networks Platform Alerts, Third-Party Alerts
ATT&CK tactics: Execution (TA0002)
ATT&CK techniques: User Execution (T1204) Native API (T1106)
Detector tags: AI Insight Fusion Analytics
Attacker's goals:
Perform multiple activities to achieve the attacker's goals in the target environment.
Investigative actions:
Investigate the causality of these alerts. Track down other suspicious activity under this causality.
- Test period:
- 12 Hours
- Deduplication:
- 1 Day