Alerts related to data source "Palo Alto Networks Firewall traffic Logs".
A Possible crypto miner was detected on a host
A Torrent client was detected on a host
A user accessed an uncommon AppID
Abnormal Communication to a Rare Domain
Abnormal connections to a dormant host from a newly seen endpoint
Abnormal RDP session to a remote host from a rarely seen host
Abnormal Recurring Communications to a Rare Domain
Authentication Attempt From a Dormant Account
Download pattern that resembles Peer to Peer traffic
Failed Connections
Failed Login For Locked-Out Account
Kerberos Pre-Auth Failures by Host
Kerberos Pre-Auth Failures by User and Host
Kerberos User Enumeration
Large Upload (FTP)
Large Upload (Generic)
Large Upload (HTTPS)
Large Upload (SMTP)
Machine Account NTLM Relay
Multiple Weakly-Encrypted Kerberos Tickets Received
New Administrative Behavior
New FTP Server
NTLM Hash Harvesting
NTLM Password Spray
NTLM Relay
Port Scan
Port Sweep
Possible DCSync from a non domain controller
Possible IPFS traffic was detected
Possible Kerberoasting without SPNs
Possible use of IPFS was detected
Rare AppID usage to a rare destination
Rare NTLM Access By User To Host
Rare process created an SSH session to an uncommon cloud resource
Rare process created an SSH session to an uncommon external host
Rare RDP session to a remote host
Rare SMB session to a remote host
Rare SMTP/S Session
RDP from an unmanaged endpoint in a typically managed subnet
Recurring access to rare IP
Recurring rare domain access to dynamic DNS domain
Spam Bot Traffic
Suspicious DNS traffic
Suspicious SMB connection from domain controller
Uncommon SSH session was established
Unusual SSH Activity
Unusual SSH activity that resembles SSH proxy
Upload pattern that resembles Peer to Peer traffic
Weakly-Encrypted Kerberos Ticket Requested
Was this helpful?