For the complete documentation index, see llms.txt. This page is also available as Markdown.

AI-determined combination of risky alerts under the same actor process

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

12 Hours

Deduplication Period

1 Day

Required Data

Requires one of the following data sources: Palo Alto Networks Platform Alerts OR Third-Party Alerts

Detector Tags

AI Insight Fusion Analytics

ATT&CK Tactic

Execution (TA0002)

ATT&CK Technique

User Execution (T1204), Native API (T1106)

Severity

Informational

Description

Multiple alerts likely to be associated with an incident were identified under the same actor process.

Attacker's Goals

Perform multiple activities to achieve the attacker's goals in the target environment.

Investigative actions

  • Investigate the actor process of these alerts.

  • Track down other suspicious activity under this actor process.

Variations

AI-determined combination of risky alerts under the same actor process: LDAP traffic from non-standard process with SMB traffic from non-standard process

Synopsis

Field
Value

ATT&CK Tactic

Execution (TA0002)

ATT&CK Technique

User Execution (T1204), Native API (T1106)

Severity

Medium

Description

A non-standard process communicated over LDAP ports, combined with SMB traffic from a non-standard process under the same actor process. This combination may indicate an attacker performing Active Directory enumeration while leveraging SMB for lateral movement or discovery.

Attacker's Goals

Perform multiple activities to achieve the attacker's goals in the target environment.

Investigative actions

  • Investigate the actor process of these alerts.

  • Track down other suspicious activity under this actor process.

Was this helpful?