Alerts related to data source "Palo Alto Networks Firewall EAL Logs".
A rare FTP user has been detected on an existing FTP server
A user accessed an uncommon AppID
A user accessed multiple time-consuming websites
Abnormal communication with a rare combination of TLS and HTTP User Agent
Abnormal network communication with a rare combination of HTTP User Agent and HTTP Server
Abnormal RPC traffic to multiple hosts
Abnormal sensitive RPC traffic to multiple hosts
Abnormal sensitive RPC traffic to multiple hosts from a rarely seen host
Bronze-Bit exploit
DNS Tunneling
Failed DNS
Failed Login For a Long Username With Special Characters
FTP Connection Using an Anonymous Login or Default Credentials
HTTP with suspicious characteristics
Increase in Job-Related Site Visits
Massive upload to a rare storage or mail domain
Multiple Suspicious FTP Login Attempts
Multiple uncommon SSH Servers with the same Server host key
Okta FastPass reported phishing attack suspected
Possible path traversal via HTTP request
Random-Looking Domain Names
Rare access to known advertising domains
Rare DCOM RPC activity
Rare LDAP enumeration
Rare MS-Update Server was detected
Rare MS-Update traffic over HTTP
Rare NTLM Usage by User
Rare Remote Service (SVCCTL) RPC activity
Rare Scheduled Task RPC activity
Rare Scheduled Task RPC activity from a rarely seen host
Rare Windows Remote Management (WinRM) HTTP Activity
Recurring access to rare domain
Subdomain Fuzzing
Suspicious Encrypting File System Remote call (EFSRPC) to domain controller
Suspicious failed HTTP request - potential Spring4Shell exploit
Suspicious HTTP parameters detected
Suspicious ICMP packet
Suspicious NTLM authentication with machine account
Suspicious SSH Downgrade
Uncommon WPAD queries
Unique client computer model was detected via MS-Update protocol
Unusual ADFS Remote Synchronization network connections from non-ADFS server
Weakly-Encrypted Kerberos TGT Response
Was this helpful?