Multiple alerts of different MITRE tactics were seen
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
3 Hours
Deduplication Period
1 Day
Required Data
Requires one of the following data sources: Palo Alto Networks Platform Alerts OR Third-Party Alerts
ATT&CK Tactic
Execution (TA0002)
ATT&CK Technique
User Execution (T1204), Native API (T1106)
Severity
Low
Description
Multiple alerts of different MITRE tactics were seen on the same host under the same causality.
Attacker's Goals
Execute multiple covert actions to circumvent detection.
Investigative actions
Investigate the causality of all the linked alerts. It is visible in the bottom of the causality page.
Assess whether it looks like a threat actor executing multiple tactics.
PreviousMultiple alerts associated with a single RDP connection
NextMultiple Azure AD admin role removals
Was this helpful?
