Non-browser access to a pastebin-like site
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
Palo Alto Networks Url Logs
ATT&CK Tactic
Command and Control (TA0011)
ATT&CK Technique
Web Service (T1102)
Severity
Low
Description
Non-browser access to a pastebin-like site.
Attacker's Goals
Data exfiltration or attack tool staging.
Investigative actions
Examine the host to verify that the host was not part of infiltration or data exfiltration from the organization.
Verify that the host doesn't have sensitive company data that can be easily exfiltrated.
Variations
PreviousNew Teams application published to the organization catalog
NextNTDS.dit file written by an uncommon executable
Was this helpful?
