Rare SMTP/S Session
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
Requires one of the following data sources: Palo Alto Networks Firewall traffic Logs OR XDR Agent OR Third-Party Firewalls
ATT&CK Tactic
Exfiltration (TA0010)
ATT&CK Technique
Exfiltration Over Alternative Protocol (T1048)
Severity
Informational
Description
The Simple Mail Transfer Protocol (SMTP) and its SSL-secured variant SMTPS are used to send email. Attackers can use SMTP/S to exfiltrate data from your network.
Attacker's Goals
SMTP and its SSL-secured variant SMTPS are used to send email. Attackers can use SMTP/S to exfiltrate data from your network.
Investigative actions
Check whether the initiator process is benign or normal for the host and/or user performing it.
Check whether additional malicious commands were executed from the same process.
Was this helpful?
