A user accessed an uncommon AppID
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
Requires all of the following: Palo Alto Networks Firewall EAL Logs OR Palo Alto Networks Firewall threat Logs OR Palo Alto Networks Firewall traffic Logs XDR Agent
Detection Modules
Identity Threat Module
ATT&CK Tactic
Exfiltration (TA0010)
ATT&CK Technique
Exfiltration Over Web Service (T1567)
Severity
Informational
Description
A user accessed an uncommon AppID that is rarely accessed by them or anyone else in the organization.
Attacker's Goals
A user accessed an uncommon AppID that is rarely accessed by them or anyone else in the organization. This may indicate an attempt to exfiltrate sensitive data.
Investigative actions
Check for any other suspicious activity related to the host and the user involved in the alert.
Variations
Was this helpful?
