Abnormal communication with a rare combination of TLS and HTTP User Agent
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
Requires one of the following data sources: Palo Alto Networks Firewall EAL Logs OR XDR Agent
ATT&CK Tactic
Command and Control (TA0011), Exfiltration (TA0010)
ATT&CK Technique
Web Service (T1102), Exfiltration Over Web Service (T1567)
Severity
Low
Description
Abnormal communication with a rare combination of TLS and HTTP User Agent to an external address.
Attacker's Goals
Data exfiltration, attack tool staging or command and control channel through a trusted service.
Investigative actions
Examine the legitimacy of the application that produced this rare TLS fingerprint with the external server.
Examine the parent process of this application.
Check for anomalies at the time when the communication occurred.
Verify if the outbound communication is being routed through a legitimate HTTP tunneling solution.
Variations
Was this helpful?
