- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
01-30-2023 10:36 PM
Hello everyone,
Recently we started getting these types of incidents in our SOC team for Cortex XDR.
It shows that the user connected with SSO using this ASN.
However, it says that the ASN 263461 is suspicious but we can't verify it with lookup tool.
Any idea how to investigate this properly?
Alert info:
01-31-2023 12:01 AM
Hi @DragomirGaliaIT ,
The alert only says the ASN is uncommon for your organization. This is different from saying ASN is suspicious.
This alert is raised by XDR Analytics, which in nutshell look for anomalies in your log data. Anomaly by itself doesn't mean something is malicious/suspicious.
In this specific case XDR notify you that user have performed SSO with IP from ASN that was not used by any other of your users for the last 30 days. It is up to your to verify if that user is currently traveling and it is expected for him to connect from such ASN (based on his geo-location).
My first suggestion is to pay more attention to the alert - it is common misconception that uncommon/rare = suspicious or malicious.
We receive similar alerts, but for GP login. So what we usually do is to check and confirm if this users is indeed traveling at the moment and if it is expected for him to connect to such ASN. If we cannot confirm this by other information we contact the user or some manager to confirm
01-31-2023 12:49 AM
Thanks for the explanation. It was indeed regular connection, user has connected using NordVPN for this. Nothing suspicious at all.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!