Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. Cortex XDR

Cortex XDR

Scheduled Pinned Locked Moved Uncategorized
3 Posts 2 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • kajer@infosec.exchangeK This user is from outside of this forum
    kajer@infosec.exchangeK This user is from outside of this forum
    kajer@infosec.exchange
    wrote last edited by
    #1

    Cortex XDR

    Alert Name: Abnormal Recurring Communications to a Rare Domain With a Less Common Port
    Alert id: ---
    Severity: Low
    Source: XDR Analytics BIOC
    Category: Command and Control
    Action: Detected
    Description: The host [$host] was seen communicating to the external entity [$domain]. Communication between these entities was seen 13 times. This external entity is rare in the organization as only 4 hosts within the organization accessed it. This external entity is also rare globally. This external entity was accessed using 1 distinct ports. Based on our machine learning models, this connection was flagged as suspicious

    hint, it was SSH.

    cybeej@infosec.exchangeC 1 Reply Last reply
    0
    • kajer@infosec.exchangeK kajer@infosec.exchange

      Cortex XDR

      Alert Name: Abnormal Recurring Communications to a Rare Domain With a Less Common Port
      Alert id: ---
      Severity: Low
      Source: XDR Analytics BIOC
      Category: Command and Control
      Action: Detected
      Description: The host [$host] was seen communicating to the external entity [$domain]. Communication between these entities was seen 13 times. This external entity is rare in the organization as only 4 hosts within the organization accessed it. This external entity is also rare globally. This external entity was accessed using 1 distinct ports. Based on our machine learning models, this connection was flagged as suspicious

      hint, it was SSH.

      cybeej@infosec.exchangeC This user is from outside of this forum
      cybeej@infosec.exchangeC This user is from outside of this forum
      cybeej@infosec.exchange
      wrote last edited by
      #2

      @kajer tbf that’s not an unreasonable reason to trigger an alert is it?

      kajer@infosec.exchangeK 1 Reply Last reply
      0
      • cybeej@infosec.exchangeC cybeej@infosec.exchange

        @kajer tbf that’s not an unreasonable reason to trigger an alert is it?

        kajer@infosec.exchangeK This user is from outside of this forum
        kajer@infosec.exchangeK This user is from outside of this forum
        kajer@infosec.exchange
        wrote last edited by
        #3

        @cybeej it is when our whole org uses SSH and these alerts trigger every 30 days to known and internal DNS

        We have attempted to exclude these from alerting, but Cortex keeps finding new, exciting, and vague ways to continue to throw alerts.

        1 Reply Last reply
        1
        0
        • R relay@relay.infosec.exchange shared this topic
        Reply
        • Reply as topic
        Log in to reply
        • Oldest to Newest
        • Newest to Oldest
        • Most Votes


        • Login

        • Login or register to search.
        • First post
          Last post
        0
        • Categories
        • Recent
        • Tags
        • Popular
        • World
        • Users
        • Groups