For the complete documentation index, see llms.txt. This page is also available as Markdown.

Analytics enhanced NGFW Threat Alert - Rare Internal Firewall Vulnerability Threat Alert

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

Requires all of the following: Palo Alto Networks Firewall threat Logs XDR Agent

ATT&CK Tactic

Reconnaissance (TA0043)

ATT&CK Technique

Active Scanning: Vulnerability Scanning (T1595.002)

Severity

Informational

Description

An internal host triggered an NGFW (Next-Generation Firewall) vulnerability threat alert targeting another internal host. This activity is highly anomalous as it deviates from the source host's historical behavior and is rarely seen targeting this specific destination across the organization.

Attacker's Goals

Adversaries may attempt to exploit a vulnerability to gain initial access, execute malicious code, or move laterally within the internal network.

Investigative actions

  • Verify the firewall alert details, including the threat name, CVE, and severity.

  • Inspect the destination internal host for signs of successful exploitation, such as suspicious processes, new files, or unusual outbound connections.

  • Determine if the source host is an internal scanner or a compromised asset.

  • Review recent changes or updates on the target system that might have exposed the vulnerability.

  • Check if the traffic was blocked by the firewall or only detected.

Variations

Analytics enhanced NGFW Threat Alert - Rare Internal Firewall Vulnerability Threat Alert Categorized as code-execution/info-leak

Synopsis

Field
Value

ATT&CK Tactic

Reconnaissance (TA0043)

ATT&CK Technique

Active Scanning: Vulnerability Scanning (T1595.002)

Severity

Informational

Description

An internal host triggered an NGFW (Next-Generation Firewall) vulnerability threat alert targeting another internal host. This activity is highly anomalous as it deviates from the source host's historical behavior and is rarely seen targeting this specific destination across the organization.

Attacker's Goals

Adversaries may attempt to exploit a vulnerability to gain initial access, execute malicious code, or move laterally within the internal network.

Investigative actions

  • Verify the firewall alert details, including the threat name, CVE, and severity.

  • Inspect the destination internal host for signs of successful exploitation, such as suspicious processes, new files, or unusual outbound connections.

  • Determine if the source host is an internal scanner or a compromised asset.

  • Review recent changes or updates on the target system that might have exposed the vulnerability.

  • Check if the traffic was blocked by the firewall or only detected.

Was this helpful?