Analytics
Informational
✕
Uncommon WPAD queries
There were multiple attempts to access WPAD resources by a single host in your network. This may indicate a malicious activity.
- Module:
- Platform Analytics
- Data source:
- Palo Alto Networks Firewall EAL Logs, XDR Agent
ATT&CK tactics: Credential Access (TA0006)
ATT&CK techniques: Adversary-in-the-Middle (T1557)
Attacker's goals:
Attackers may attempt to move laterally over the network by exploiting problems in WPAD.
Investigative actions:
Verify that the source host is legitimate.* Examine the legitimacy of the application that produced this uncommon WPAD. Examine the parent process of this application.
- Test period:
- 1 Hour
- Deduplication:
- 1 Day
3 variations:
- Uncommon WPAD queries to a external domain Informational
- Suspicious WPAD queries Low (parent: Informational)
- Uncommon WPAD queries using an uncommon port Informational