Abnormal network communication with a rare combination of HTTP User Agent and HTTP Server
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
Requires one of the following data sources: Palo Alto Networks Firewall EAL Logs OR XDR Agent
ATT&CK Tactic
Command and Control (TA0011), Exfiltration (TA0010)
ATT&CK Technique
Web Service (T1102), Exfiltration Over Web Service (T1567)
Severity
Informational
Description
Abnormal network communication with a rare combination of HTTP User Agent and HTTP Server to an external address.
Attacker's Goals
Data exfiltration, attack tool staging or command and control channel through a trusted service.
Investigative actions
Examine the legitimacy of the application that produced this rare combination of HTTP User Agent with the external HTTP Server.
Examine the parent process of this application.
Check for anomalies at the time when the communication occurred.
Variations
Was this helpful?
