> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/large-upload-generic.md).

# Large Upload (Generic)

### Synopsis

| Field                | Value                                                                                                       |
| -------------------- | ----------------------------------------------------------------------------------------------------------- |
| Activation Period    | 14 Days                                                                                                     |
| Training Period      | 30 Days                                                                                                     |
| Test Period          | 1 Day                                                                                                       |
| Deduplication Period | 1 Day                                                                                                       |
| Required Data        | <p>Requires one of the following data sources:<br>Palo Alto Networks Firewall traffic Logs OR XDR Agent</p> |
| ATT\&CK Tactic       | Exfiltration (TA0010)                                                                                       |
| ATT\&CK Technique    | Exfiltration Over Alternative Protocol (T1048)                                                              |
| Severity             | Low                                                                                                         |

### Description

The endpoint transferred large amounts of data to an external site using a different protocol from HTTP/s, FTP, or SMTP. (A specific detector is used for each of those protocols.) Cortex XDR Analytics assumes that data transfers out of your network are ordinarily performed using one of those three services, so it expects that data transfers over all other ports to be low. For the same reason, Cortex XDR Analytics also assumes endpoint traffic towards a specific destination should be about the same over long periods of time. An attacker may be exfiltrating data directly to the internet.

### Attacker's Goals

Transfer data he has stolen from your network to a location that is convenient and useful to him.

### Investigative actions

* Check if the traffic is related to SSH activity, it can trigger this alert. It is possible that someone on your network is legitimately engaged in SSH activity.
* Check if the traffic is to/from a misconfigured network.
* Check if the traffic is to a new external service or server that has recently been adopted for use by an organization in your enterprise.
* Identify the process/user performing the data transfer to determine if the transfer is sanctioned.

### Variations

<details>

<summary>Large Upload (Generic)</summary>

**Synopsis**

| Field             | Value                                          |
| ----------------- | ---------------------------------------------- |
| ATT\&CK Tactic    | Exfiltration (TA0010)                          |
| ATT\&CK Technique | Exfiltration Over Alternative Protocol (T1048) |
| Severity          | Informational                                  |

**Description**

The endpoint transferred large amounts of data to an external site using a different protocol from HTTP/s, FTP, or SMTP. (A specific detector is used for each of those protocols.) Cortex XDR Analytics assumes that data transfers out of your network are ordinarily performed using one of those three services, so it expects that data transfers over all other ports to be low. For the same reason, Cortex XDR Analytics also assumes endpoint traffic towards a specific destination should be about the same over long periods of time. An attacker may be exfiltrating data directly to the internet.

**Attacker's Goals**

Transfer data he has stolen from your network to a location that is convenient and useful to him.

**Investigative actions**

* Check if the traffic is related to SSH activity, it can trigger this alert. It is possible that someone on your network is legitimately engaged in SSH activity.
* Check if the traffic is to/from a misconfigured network.
* Check if the traffic is to a new external service or server that has recently been adopted for use by an organization in your enterprise.
* Identify the process/user performing the data transfer to determine if the transfer is sanctioned.

</details>

<details>

<summary>Large Upload (Generic) Lower than 100 MB</summary>

**Synopsis**

| Field             | Value                                          |
| ----------------- | ---------------------------------------------- |
| ATT\&CK Tactic    | Exfiltration (TA0010)                          |
| ATT\&CK Technique | Exfiltration Over Alternative Protocol (T1048) |
| Severity          | Informational                                  |

**Description**

The endpoint transferred large amounts of data to an external site using a different protocol from HTTP/s, FTP, or SMTP. (A specific detector is used for each of those protocols.) Cortex XDR Analytics assumes that data transfers out of your network are ordinarily performed using one of those three services, so it expects that data transfers over all other ports to be low. For the same reason, Cortex XDR Analytics also assumes endpoint traffic towards a specific destination should be about the same over long periods of time. An attacker may be exfiltrating data directly to the internet.

**Attacker's Goals**

Transfer data he has stolen from your network to a location that is convenient and useful to him.

**Investigative actions**

* Check if the traffic is related to SSH activity, it can trigger this alert. It is possible that someone on your network is legitimately engaged in SSH activity.
* Check if the traffic is to/from a misconfigured network.
* Check if the traffic is to a new external service or server that has recently been adopted for use by an organization in your enterprise.
* Identify the process/user performing the data transfer to determine if the transfer is sanctioned.

</details>

<details>

<summary>Large Upload (Generic) to a Frequently Used Upload Target</summary>

**Synopsis**

| Field             | Value                                          |
| ----------------- | ---------------------------------------------- |
| ATT\&CK Tactic    | Exfiltration (TA0010)                          |
| ATT\&CK Technique | Exfiltration Over Alternative Protocol (T1048) |
| Severity          | Informational                                  |

**Description**

The endpoint transferred large amounts of data to an external site using a different protocol from HTTP/s, FTP, or SMTP. (A specific detector is used for each of those protocols.) Cortex XDR Analytics assumes that data transfers out of your network are ordinarily performed using one of those three services, so it expects that data transfers over all other ports to be low. For the same reason, Cortex XDR Analytics also assumes endpoint traffic towards a specific destination should be about the same over long periods of time. An attacker may be exfiltrating data directly to the internet.

**Attacker's Goals**

Transfer data he has stolen from your network to a location that is convenient and useful to him.

**Investigative actions**

* Check if the traffic is related to SSH activity, it can trigger this alert. It is possible that someone on your network is legitimately engaged in SSH activity.
* Check if the traffic is to/from a misconfigured network.
* Check if the traffic is to a new external service or server that has recently been adopted for use by an organization in your enterprise.
* Identify the process/user performing the data transfer to determine if the transfer is sanctioned.

</details>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/large-upload-generic.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
