<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: First SSO access from an uncommon ASN by user in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/first-sso-access-from-an-uncommon-asn-by-user/m-p/529269#M3509</link>
    <description>&lt;P&gt;Thanks for the explanation. It was indeed regular connection, user has connected using NordVPN for this. Nothing suspicious at all.&lt;/P&gt;</description>
    <pubDate>Tue, 31 Jan 2023 08:49:59 GMT</pubDate>
    <dc:creator>DragomirGaliaIT</dc:creator>
    <dc:date>2023-01-31T08:49:59Z</dc:date>
    <item>
      <title>First SSO access from an uncommon ASN by user</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/first-sso-access-from-an-uncommon-asn-by-user/m-p/529242#M3502</link>
      <description>&lt;P&gt;Hello everyone,&lt;BR /&gt;&lt;BR /&gt;Recently we started getting these types of incidents in our SOC team for Cortex XDR.&lt;BR /&gt;&lt;BR /&gt;It shows that the user connected with SSO using this ASN.&lt;BR /&gt;&lt;BR /&gt;However, it says that the ASN 263461 is suspicious but we can't verify it with lookup tool.&lt;BR /&gt;&lt;BR /&gt;Any idea how to investigate this properly?&lt;BR /&gt;&lt;BR /&gt;Alert info:&lt;/P&gt;
&lt;DIV class="" style="overflow: hidden; height: 66px;"&gt;
&lt;DIV class="" style="overflow: hidden; text-overflow: ellipsis; display: -webkit-box; -moz-box-orient: vertical; -webkit-line-clamp: 3;" title="The user axis\rickardk successfully authenticated via SSO. The user accessed SSO via ASN 263461. This ASN is used by 0 users in the organization. The user has not used this ASN in the past 30 days"&gt;&lt;SPAN class=""&gt;The user&amp;nbsp; successfully authenticated via SSO. The user accessed SSO via ASN 263461. This ASN is used by 0 users in the organization. The user has not used this ASN in the past 30 days.&lt;BR /&gt;&lt;BR /&gt;Let me know if there's any other info that you need in order to help me out.&lt;BR /&gt;&lt;BR /&gt;Best regards.&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Tue, 31 Jan 2023 06:36:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/first-sso-access-from-an-uncommon-asn-by-user/m-p/529242#M3502</guid>
      <dc:creator>DragomirGaliaIT</dc:creator>
      <dc:date>2023-01-31T06:36:10Z</dc:date>
    </item>
    <item>
      <title>Re: First SSO access from an uncommon ASN by user</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/first-sso-access-from-an-uncommon-asn-by-user/m-p/529262#M3506</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/269217"&gt;@DragomirGaliaIT&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;The alert only says the ASN is uncommon for your organization. This is different from saying ASN is suspicious.&lt;/P&gt;
&lt;P&gt;This alert is raised by XDR Analytics, which in nutshell look for anomalies in your log data. Anomaly by itself doesn't mean something is malicious/suspicious.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In this specific case XDR notify you that user have performed SSO&amp;nbsp; with IP from ASN that was not used by any other of your users for the last 30 days. It is up to your to verify if that user is currently traveling and it is expected for him to connect from such ASN (based on his geo-location).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My first suggestion is to pay more attention to the alert&amp;nbsp; - it is common misconception that uncommon/rare = suspicious or malicious.&lt;/P&gt;
&lt;P&gt;We receive similar alerts, but for GP login. So what we usually do is to check and confirm if this users is indeed traveling at the moment and if it is expected for him to connect to such ASN. If we cannot confirm this by other information we contact the user or some manager to confirm&lt;/P&gt;</description>
      <pubDate>Tue, 31 Jan 2023 08:01:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/first-sso-access-from-an-uncommon-asn-by-user/m-p/529262#M3506</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2023-01-31T08:01:40Z</dc:date>
    </item>
    <item>
      <title>Re: First SSO access from an uncommon ASN by user</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/first-sso-access-from-an-uncommon-asn-by-user/m-p/529269#M3509</link>
      <description>&lt;P&gt;Thanks for the explanation. It was indeed regular connection, user has connected using NordVPN for this. Nothing suspicious at all.&lt;/P&gt;</description>
      <pubDate>Tue, 31 Jan 2023 08:49:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/first-sso-access-from-an-uncommon-asn-by-user/m-p/529269#M3509</guid>
      <dc:creator>DragomirGaliaIT</dc:creator>
      <dc:date>2023-01-31T08:49:59Z</dc:date>
    </item>
  </channel>
</rss>

