A non-browser process accessed a website UI
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
Palo Alto Networks Url Logs
ATT&CK Tactic
Command and Control (TA0011)
ATT&CK Technique
Web Service (T1102)
Severity
Informational
Description
An uncommon network communication between a non-browser process and a website UI.
Attacker's Goals
Data exfiltration or attack tool staging.
Investigative actions
Examine the host to verify that the host was not part of infiltration or data exfiltration from the organization.
Verify that the host doesn't have sensitive company data that can be easily exfiltrated.
Variations
PreviousA New Server was Added to an Azure Active Directory Hybrid Health ADFS Environment
NextA Possible crypto miner was detected on a host
Was this helpful?
