<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Abnormal Recurring Communications to a Rare IP in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/abnormal-recurring-communications-to-a-rare-ip/m-p/649057#M7461</link>
    <description>&lt;P&gt;They recently added this and it is making a ton of noise I would suggest tuning it out for now.&lt;/P&gt;</description>
    <pubDate>Fri, 22 Nov 2024 09:13:56 GMT</pubDate>
    <dc:creator>AvesterFahimipour</dc:creator>
    <dc:date>2024-11-22T09:13:56Z</dc:date>
    <item>
      <title>Abnormal Recurring Communications to a Rare IP</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/abnormal-recurring-communications-to-a-rare-ip/m-p/623611#M7438</link>
      <description>&lt;P&gt;We are receiving multiple alerts from the rule below. All alerts are legitimate Microsoft IPs:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Abnormal Recurring Communications to a Rare IP&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Could there have been any recent changes on the Cortex end that might be triggering this?&lt;BR /&gt;&lt;LI-PRODUCT title="Cortex XDR" id="Cortex_XDR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Nov 2024 17:12:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/abnormal-recurring-communications-to-a-rare-ip/m-p/623611#M7438</guid>
      <dc:creator>RajeshPremSingh</dc:creator>
      <dc:date>2024-11-18T17:12:51Z</dc:date>
    </item>
    <item>
      <title>Re: Abnormal Recurring Communications to a Rare IP</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/abnormal-recurring-communications-to-a-rare-ip/m-p/627248#M7443</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/262549"&gt;@RajeshPremSingh&lt;/a&gt;, thanks for reaching us using the Live Community.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That's an Analytics alert which means that the connections are not usual to the destination IPs, that doesn't mean that those IPs are malicious.&lt;/P&gt;
&lt;P&gt;In our Analytic Alerts Reference you can find some investigation actions for this rule (and many others if needed):&amp;nbsp;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Analytics-Alert-Reference-by-data-source/Abnormal-Recurring-Communications-to-a-Rare-IP?tocId=NR8ZpammoR77K6omQMWajQ" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Analytics-Alert-Reference-by-data-source/Abnormal-Recurring-Communications-to-a-Rare-IP?tocId=NR8ZpammoR77K6omQMWajQ&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If this post answers your question, please mark it as the solution.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Nov 2024 14:53:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/abnormal-recurring-communications-to-a-rare-ip/m-p/627248#M7443</guid>
      <dc:creator>jmazzeo</dc:creator>
      <dc:date>2024-11-19T14:53:06Z</dc:date>
    </item>
    <item>
      <title>Re: Abnormal Recurring Communications to a Rare IP</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/abnormal-recurring-communications-to-a-rare-ip/m-p/640731#M7451</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/310428"&gt;@jmazzeo&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Thanks for your reply. I have a few questions:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Data Sources for Alerts&lt;/STRONG&gt;:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Where is the data for the alert "Abnormal Recurring Communications to a Rare IP" coming from?&lt;/LI&gt;
&lt;LI&gt;eg :Possible sources include browsing history, cookie cache, DNS logs, etc.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Machine Learning Models&lt;/STRONG&gt;:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;The alert mentions, "Based on our machine learning models, this connection was flagged as suspicious."&lt;/LI&gt;
&lt;LI&gt;How does this work since it is a new BIOC rule and is still learning?&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Wed, 20 Nov 2024 20:33:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/abnormal-recurring-communications-to-a-rare-ip/m-p/640731#M7451</guid>
      <dc:creator>RajeshPremSingh</dc:creator>
      <dc:date>2024-11-20T20:33:39Z</dc:date>
    </item>
    <item>
      <title>Re: Abnormal Recurring Communications to a Rare IP</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/abnormal-recurring-communications-to-a-rare-ip/m-p/649057#M7461</link>
      <description>&lt;P&gt;They recently added this and it is making a ton of noise I would suggest tuning it out for now.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Nov 2024 09:13:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/abnormal-recurring-communications-to-a-rare-ip/m-p/649057#M7461</guid>
      <dc:creator>AvesterFahimipour</dc:creator>
      <dc:date>2024-11-22T09:13:56Z</dc:date>
    </item>
  </channel>
</rss>

