Multiple network-related alerts of different MITRE tactics on the same host
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
1 Day
Deduplication Period
1 Day
Required Data
Requires one of the following data sources: Palo Alto Networks Platform Alerts OR Third-Party Alerts
Detector Tags
NDR Insights Analytics
ATT&CK Tactic
Execution (TA0002)
ATT&CK Technique
User Execution (T1204)
Severity
Low
Description
Multiple alerts of different MITRE tactics were seen on the same host.
Attacker's Goals
Execute multiple covert actions to circumvent detection.
Investigative actions
Investigate the source of all the linked alerts.
Asses whether it looks like a threat actor executing multiple tactics.
PreviousMultiple failed logins from a single IP
NextMultiple network-related alerts produced by different detectors on the same host
Was this helpful?
