Analytics enhanced NGFW Threat Alert - Rare Internal Firewall Vulnerability Threat Alert
An internal host triggered an NGFW (Next-Generation Firewall) vulnerability threat alert targeting another internal host. This activity is highly anomalous as it deviates from the source host's historical behavior and is rarely seen targeting this specific destination across the organization.
- Module:
- Platform Analytics
- Data source:
- Palo Alto Networks Firewall threat Logs, XDR Agent
Adversaries may attempt to exploit a vulnerability to gain initial access, execute malicious code, or move laterally within the internal network.
Verify the firewall alert details, including the threat name, CVE, and severity. Inspect the destination internal host for signs of successful exploitation, such as suspicious processes, new files, or unusual outbound connections. Determine if the source host is an internal scanner or a compromised asset. Review recent changes or updates on the target system that might have exposed the vulnerability. Check if the traffic was blocked by the firewall or only detected.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
- Analytics enhanced NGFW Threat Alert - Rare Internal Firewall Vulnerability Threat Alert Categorized as code-execution/info-leak Informational