Rare AppID usage to a rare destination
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
14 Days
Required Data
Requires one of the following data sources: Palo Alto Networks Firewall traffic Logs OR XDR Agent OR Third-Party Firewalls
ATT&CK Tactic
Command and Control (TA0011)
ATT&CK Technique
Application Layer Protocol (T1071), Non-Standard Port (T1571)
Severity
Informational
Description
Rare AppID with port usage to rare destination.
Attacker's Goals
Attackers might use well-known ports with uncommon applications to avoid being detected by a non-application aware firewall or to bypass firewall rules based only on ports.
Investigative actions
Investigate the endpoints participating in the session.
Variations
Was this helpful?
