For the complete documentation index, see llms.txt. This page is also available as Markdown.

Abnormal sensitive RPC traffic to multiple hosts from a rarely seen host

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

5 Hours

Deduplication Period

1 Day

Required Data

Requires one of the following data sources: Palo Alto Networks Firewall EAL Logs OR XDR Agent with eXtended Threat Hunting (XTH)

Detector Tags

NDR Lateral Movement Analytics, NDR Unmanaged Subnet Analytics

ATT&CK Tactic

Lateral Movement (TA0008)

ATT&CK Technique

Remote Services (T1021)

Severity

Low

Description

The endpoint performed unfamiliar RPC activity to multiple hosts using a known sensitive interface.

Attacker's Goals

An adversary may enumerate different protocols to gain information and plan its lateral movement over the network.

Investigative actions

  • Check if the host is a newly deployed server that provides RPC based services to multiple hosts.

  • Verify the legitimacy of the actor process (and its causality) that initiated this RPC traffic.

Was this helpful?