Analytics
Low
✕
Multiple Suspicious FTP Login Attempts
Multiple suspicious FTP sessions were detected, which may indicate a brute-force attempt.
- Module:
- Platform Analytics
- Data source:
- Palo Alto Networks Firewall EAL Logs
ATT&CK tactics: Initial Access (TA0001) Credential Access (TA0006)
ATT&CK techniques: Brute Force (T1110) Valid Accounts (T1078)
Attacker's goals:
Attackers may seek access to FTP accounts and use them to exfiltrate data, stage attack tools, or create command and control channels through trusted services.
Investigative actions:
Examine the legitimacy of the application that produced this uncommon FTP connection. Examine the parent process of this application. Verify that the connection attempts were not performed from an illegitimate source.
- Test period:
- 2 Hours
- Deduplication:
- 1 Day