FTP Connection Using an Anonymous Login or Default Credentials
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
Palo Alto Networks Firewall EAL Logs
ATT&CK Tactic
Initial Access (TA0001), Credential Access (TA0006)
ATT&CK Technique
Brute Force (T1110), Valid Accounts (T1078)
Severity
Low
Description
An FTP connection using an anonymous login was detected.
Attacker's Goals
Attackers may seek access to FTP accounts and use them to exfiltrate data, stage attack tools, or create command and control channels through trusted services.
Investigative actions
Examine the legitimacy of the application that produced this FTP.
Examine the parent process of this application.
Verify that the connection attempts were not performed from an illegitimate source.
PreviousForeign account was granted permissions to S3 bucket via resource-based policy
NextGCP administrative role granted to a cloud identity
Was this helpful?
