cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Who rated this post

As the signature name indicates, the common username was found in HTTP Basic Authentication, in other words, it was found in the traffic that the firewall saw. It doesn't mean that the common username exists on the server.


If you collect the threat pcap, you should be able to see what username is used in the traffic.

Reference:
https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/monitoring/take-packet-captures/take-a-th...

 

Who rated this post