Analytics Informational

Uncommon WPAD queries

There were multiple attempts to access WPAD resources by a single host in your network. This may indicate a malicious activity.

Module:
Platform Analytics
Data source:
Palo Alto Networks Firewall EAL Logs, XDR Agent
ATT&CK tactics: Credential Access (TA0006)
ATT&CK techniques: Adversary-in-the-Middle (T1557)
Attacker's goals:

Attackers may attempt to move laterally over the network by exploiting problems in WPAD.

Investigative actions:

Verify that the source host is legitimate.* Examine the legitimacy of the application that produced this uncommon WPAD. Examine the parent process of this application.

Test period:
1 Hour
Deduplication:
1 Day
3 variations:
  • Uncommon WPAD queries to a external domain Informational
  • Suspicious WPAD queries Low (parent: Informational)
  • Uncommon WPAD queries using an uncommon port Informational