Analytics Low

Multiple Suspicious FTP Login Attempts

Multiple suspicious FTP sessions were detected, which may indicate a brute-force attempt.

Module:
Platform Analytics
Data source:
Palo Alto Networks Firewall EAL Logs
ATT&CK tactics: Initial Access (TA0001) Credential Access (TA0006)
ATT&CK techniques: Brute Force (T1110) Valid Accounts (T1078)
Attacker's goals:

Attackers may seek access to FTP accounts and use them to exfiltrate data, stage attack tools, or create command and control channels through trusted services.

Investigative actions:

Examine the legitimacy of the application that produced this uncommon FTP connection. Examine the parent process of this application. Verify that the connection attempts were not performed from an illegitimate source.

Test period:
2 Hours
Deduplication:
1 Day