Analytics
Low
✕
HTTP with suspicious characteristics
Uncommon HTTP communication was performed by the host that might indicate its attempt to hide malicious activities.
- Module:
- Platform Analytics
- Data source:
- Palo Alto Networks Firewall EAL Logs, XDR Agent
ATT&CK tactics: Command and Control (TA0011) Exfiltration (TA0010)
ATT&CK techniques: Web Service (T1102) Exfiltration Over Web Service (T1567)
Attacker's goals:
Data exfiltration, attack tool staging or command and control channel through a trusted service.
Investigative actions:
Examine the legitimacy of the application that produced this uncommon connection. Examine the parent process of this application. Check for anomalies at the time when the communication occurred.
- Test period:
- 2 Hours
- Deduplication:
- 1 Day
3 variations:
- HTTP with suspicious characteristics which is repetitive Low
- HTTP with suspicious characteristics to an IP address Low
- HTTP with suspicious characteristics that always fails Informational (parent: Low)