<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic About Correlation Object Detection in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/about-correlation-object-detection/m-p/617602#M5002</link>
    <description>&lt;P&gt;Attention: JAPAC TPM team&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would like to know the following about Correlation Object (Beacon Detection) event generation.&lt;BR /&gt;We recognize that Beacon Detection defines how many times a malicious activity (e.g. access to threat URL) in a given period of time from the following descriptions.&lt;BR /&gt;&lt;BR /&gt;[Correlation Object]&lt;BR /&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/monitoring/use-the-automated-correlation-engine/automated-correlation-engine-concepts/correlation-object" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/monitoring/use-the-automated-correlation-engine/automated-correlation-engine-concepts/correlation-object&lt;/A&gt;&lt;BR /&gt;-----&lt;BR /&gt;Each pattern has a severity rating, and a threshold for the number of times the pattern match must occur within a defined time limit to indicate malicious activity.&lt;BR /&gt;When the match conditions are met, a correlated event is logged.&lt;BR /&gt;-----&lt;BR /&gt;&lt;BR /&gt;WebGUI description of Beacon Detection (Monitor &amp;gt; Automated Correlation Engine &amp;gt; Correlation Objects):&lt;BR /&gt;-----&lt;BR /&gt;This correlation object detects likely compromised hosts based on activity that resembles command-and-control (C2) beaconing, such as repeated visits to recently registered domains or dynamic DNS domains, repeated file downloads from the same location, generation of unknown traffic, etc.&lt;BR /&gt;-----&lt;BR /&gt;&lt;BR /&gt;About the Beacon Detection,&lt;BR /&gt;Can you please tell me the exact value of a threshold for the number of times?&lt;BR /&gt;Also, can you tell us how long period is specified to detect malicious activity?&lt;/P&gt;</description>
    <pubDate>Thu, 14 Nov 2024 03:24:45 GMT</pubDate>
    <dc:creator>Kawariver</dc:creator>
    <dc:date>2024-11-14T03:24:45Z</dc:date>
    <item>
      <title>About Correlation Object Detection</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/about-correlation-object-detection/m-p/617602#M5002</link>
      <description>&lt;P&gt;Attention: JAPAC TPM team&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would like to know the following about Correlation Object (Beacon Detection) event generation.&lt;BR /&gt;We recognize that Beacon Detection defines how many times a malicious activity (e.g. access to threat URL) in a given period of time from the following descriptions.&lt;BR /&gt;&lt;BR /&gt;[Correlation Object]&lt;BR /&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/monitoring/use-the-automated-correlation-engine/automated-correlation-engine-concepts/correlation-object" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/monitoring/use-the-automated-correlation-engine/automated-correlation-engine-concepts/correlation-object&lt;/A&gt;&lt;BR /&gt;-----&lt;BR /&gt;Each pattern has a severity rating, and a threshold for the number of times the pattern match must occur within a defined time limit to indicate malicious activity.&lt;BR /&gt;When the match conditions are met, a correlated event is logged.&lt;BR /&gt;-----&lt;BR /&gt;&lt;BR /&gt;WebGUI description of Beacon Detection (Monitor &amp;gt; Automated Correlation Engine &amp;gt; Correlation Objects):&lt;BR /&gt;-----&lt;BR /&gt;This correlation object detects likely compromised hosts based on activity that resembles command-and-control (C2) beaconing, such as repeated visits to recently registered domains or dynamic DNS domains, repeated file downloads from the same location, generation of unknown traffic, etc.&lt;BR /&gt;-----&lt;BR /&gt;&lt;BR /&gt;About the Beacon Detection,&lt;BR /&gt;Can you please tell me the exact value of a threshold for the number of times?&lt;BR /&gt;Also, can you tell us how long period is specified to detect malicious activity?&lt;/P&gt;</description>
      <pubDate>Thu, 14 Nov 2024 03:24:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/about-correlation-object-detection/m-p/617602#M5002</guid>
      <dc:creator>Kawariver</dc:creator>
      <dc:date>2024-11-14T03:24:45Z</dc:date>
    </item>
  </channel>
</rss>

