Analytics Low

HTTP with suspicious characteristics

Uncommon HTTP communication was performed by the host that might indicate its attempt to hide malicious activities.

Module:
Platform Analytics
Data source:
Palo Alto Networks Firewall EAL Logs, XDR Agent
ATT&CK tactics: Command and Control (TA0011) Exfiltration (TA0010)
ATT&CK techniques: Web Service (T1102) Exfiltration Over Web Service (T1567)
Attacker's goals:

Data exfiltration, attack tool staging or command and control channel through a trusted service.

Investigative actions:

Examine the legitimacy of the application that produced this uncommon connection. Examine the parent process of this application. Check for anomalies at the time when the communication occurred.

Test period:
2 Hours
Deduplication:
1 Day
3 variations:
  • HTTP with suspicious characteristics which is repetitive Low
  • HTTP with suspicious characteristics to an IP address Low
  • HTTP with suspicious characteristics that always fails Informational (parent: Low)