<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Alert from which source/rule? in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/alert-from-which-source-rule/m-p/511118#M2470</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/190671"&gt;@RFeyertag&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Additionally&amp;nbsp; to what Afurze mentioned (with very good criteria by the way) inspecting the alert on our documentation, please investigate the specific endpoint. And maybe talk to the user and/or manager of the endpoint group to see if this endpoint has changed the role in the organization, maybe now it is used to transfer legit info to a legit site ? (customer of yours, provider, other organization you cooperate with...) check with them and also with XDR if a new app has been installed there a bit earlier than the exfiltration ocurred, if the user logged in by the time of potential exfiltration was a legit one and also if the time of data transfer is "normal business hours??", check the type of loggin of the user by that time, was he sitting on the endpoint ? was it a remote/network login ? the IP of the connection in case of the user was remotely connecting ? is it legit location ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Maybe investigating the CGO you can find the app/process that is the culprit of the suspicious action ?&lt;/P&gt;
&lt;P&gt;Having our Identity Analytics (and so Cloud Identity Engine) enabled will also focus through AD data on the behaviour over time of the suspected user and endpoint.&amp;nbsp;&lt;BR /&gt;Just some clues to perform the incident investigation and the determination of the actual root cause of the incident.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Luis&lt;/P&gt;</description>
    <pubDate>Fri, 05 Aug 2022 14:00:25 GMT</pubDate>
    <dc:creator>eluis</dc:creator>
    <dc:date>2022-08-05T14:00:25Z</dc:date>
    <item>
      <title>Alert from which source/rule?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/alert-from-which-source-rule/m-p/511029#M2460</link>
      <description>&lt;P&gt;Hello!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have some alerts which show us a large upload.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="RFeyertag_0-1659634616953.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/42983i1419BFABF17CFCCB/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="RFeyertag_0-1659634616953.png" alt="RFeyertag_0-1659634616953.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My problem is now, I saw other clients uploading a ton of bytes, but this Alert wasn't fired.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I also cannot find any Rule for this.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Where is it comming from?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Rob&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Aug 2022 17:42:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/alert-from-which-source-rule/m-p/511029#M2460</guid>
      <dc:creator>RFeyertag</dc:creator>
      <dc:date>2022-08-04T17:42:45Z</dc:date>
    </item>
    <item>
      <title>Re: Alert from which source/rule?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/alert-from-which-source-rule/m-p/511049#M2462</link>
      <description>&lt;P&gt;Hi RFeyertag,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-unlink="true"&gt;This is an Analytics alert, specifically&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-analytics-alert-reference/cortex-xdr-analytics-alert-reference/large-upload-https" target="_self"&gt;Large Upload (https)&lt;/A&gt;. The Analytics engine examines data from the XDR agents which have Pro capabilities enabled as well as NGFW logs if you have a Pro per TB license.&amp;nbsp; The Analytics Engine creates a baseline of normal activity in the environment and then looks for anomalies, each alert has its own baseline period and test period, you can read more in the link above for this specific alert.&lt;/P&gt;
&lt;P data-unlink="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-unlink="true"&gt;The rule does not look only at upload size, it is also looking for sites that clients are not uploading large amounts of data to and that the endpoint in question has not downloaded a large amount of data from.&amp;nbsp; The check is to look for potential data exfiltration from your network.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Aug 2022 18:05:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/alert-from-which-source-rule/m-p/511049#M2462</guid>
      <dc:creator>afurze</dc:creator>
      <dc:date>2022-08-04T18:05:18Z</dc:date>
    </item>
    <item>
      <title>Re: Alert from which source/rule?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/alert-from-which-source-rule/m-p/511063#M2463</link>
      <description>&lt;P&gt;Thanks a lot!&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":smiling_face_with_smiling_eyes:"&gt;😊&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Aug 2022 18:17:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/alert-from-which-source-rule/m-p/511063#M2463</guid>
      <dc:creator>RFeyertag</dc:creator>
      <dc:date>2022-08-04T18:17:26Z</dc:date>
    </item>
    <item>
      <title>Re: Alert from which source/rule?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/alert-from-which-source-rule/m-p/511118#M2470</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/190671"&gt;@RFeyertag&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Additionally&amp;nbsp; to what Afurze mentioned (with very good criteria by the way) inspecting the alert on our documentation, please investigate the specific endpoint. And maybe talk to the user and/or manager of the endpoint group to see if this endpoint has changed the role in the organization, maybe now it is used to transfer legit info to a legit site ? (customer of yours, provider, other organization you cooperate with...) check with them and also with XDR if a new app has been installed there a bit earlier than the exfiltration ocurred, if the user logged in by the time of potential exfiltration was a legit one and also if the time of data transfer is "normal business hours??", check the type of loggin of the user by that time, was he sitting on the endpoint ? was it a remote/network login ? the IP of the connection in case of the user was remotely connecting ? is it legit location ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Maybe investigating the CGO you can find the app/process that is the culprit of the suspicious action ?&lt;/P&gt;
&lt;P&gt;Having our Identity Analytics (and so Cloud Identity Engine) enabled will also focus through AD data on the behaviour over time of the suspected user and endpoint.&amp;nbsp;&lt;BR /&gt;Just some clues to perform the incident investigation and the determination of the actual root cause of the incident.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Luis&lt;/P&gt;</description>
      <pubDate>Fri, 05 Aug 2022 14:00:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/alert-from-which-source-rule/m-p/511118#M2470</guid>
      <dc:creator>eluis</dc:creator>
      <dc:date>2022-08-05T14:00:25Z</dc:date>
    </item>
  </channel>
</rss>

