Alerts related to data source "Palo Alto Networks Global Protect".
A disabled user attempted to log in to a VPN
A Successful VPN connection from TOR
A user connected to a VPN from a new country
A user logged in at an unusual time via VPN
Azure Privilege Escalation Using an Application
First VPN access attempt from a country in organization
First VPN access from ASN for user
First VPN access from ASN in organization
Impossible traveler - VPN
Possible Insider Threat Activity
Possible phishing attack via Microsoft Teams
Potential extraction of NAA Account Credentials in Microsoft Configuration Manager
VPN access with an abnormal operating system
VPN login attempt by a honey user
VPN login Brute-Force attempt
VPN login by a dormant user
VPN login by a service account
VPN Login Password Spray
VPN login with a machine account
Was this helpful?