We are see numerous alarms from our SIEM from our Palo Alto firewall. Here is a copy of a scrubbed log message below. When asking the user about their activity, they only RDP'ed into various servers from their laptop via the Globalprotect VPN for remote admin work and ran a batch file that re-maps drives. Additionally they noted browsing to \\<dcserver>\netlogon and that it seem to take long to enumerate directory. Also full AV endpoint scans show clean. Is this s false-positive?
... View more