For the complete documentation index, see llms.txt. This page is also available as Markdown.

Abnormal sensitive RPC traffic to multiple hosts

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

5 Hours

Deduplication Period

1 Day

Required Data

Requires one of the following data sources: Palo Alto Networks Firewall EAL Logs OR XDR Agent with eXtended Threat Hunting (XTH)

Detector Tags

NDR Lateral Movement Analytics

ATT&CK Tactic

Lateral Movement (TA0008)

ATT&CK Technique

Remote Services (T1021)

Severity

Low

Description

The endpoint performed unfamiliar RPC activity to multiple hosts using a known sensitive interface.

Attacker's Goals

An adversary may enumerate different protocols to gain information and plan its lateral movement over the network.

Investigative actions

  • Check if the host is a newly deployed server that provides RPC based services to multiple hosts.

  • Verify the legitimacy of the actor process (and its causality) that initiated this RPC traffic.

Variations

Abnormal sensitive RPC traffic to multiple IPs

Synopsis

Field
Value

ATT&CK Tactic

Lateral Movement (TA0008)

ATT&CK Technique

Remote Services (T1021)

Severity

Informational

Description

The endpoint performed unfamiliar RPC activity to multiple hosts using a known sensitive interface.

Attacker's Goals

An adversary may enumerate different protocols to gain information and plan its lateral movement over the network.

Investigative actions

  • Check if the host is a newly deployed server that provides RPC based services to multiple hosts.

  • Verify the legitimacy of the actor process (and its causality) that initiated this RPC traffic.

Was this helpful?