Product
Cross-Telemetry Correlation of Endpoint and Network Security Alerts
3 TTPsDetection engineering logic that correlates Elastic Defend endpoint alerts with network security events from PAN-OS, FortiGate, and Suricata to identify potentially compromised hosts based on multi-source telemetry.
Correlation of Palo Alto Networks C2 Alerts with Endpoint Process Activity
1 TTPThis detection capability correlates Palo Alto Networks (PANW) firewall command and control alerts with Elastic Defend endpoint events to identify the specific process responsible for network traffic flagged as malicious.
Adversary Use of RAR and PowerShell Downloads for Tooling Delivery
1 rule 1 TTPAdversaries, including FIN7, utilize the downloading of RAR archives and PowerShell scripts from external sources to retrieve encoded or encrypted payloads to facilitate initial access and lateral movement.
Information Disclosure Vulnerability in PAN-OS URL Filtering
1 TTPAn information disclosure vulnerability (CVE-2026-0301) in Palo Alto Networks PAN-OS URL Filtering allows unauthenticated attackers to access sensitive memory data if custom response pages are enabled.
CVE-2026-0257 PAN-OS GlobalProtect Authentication Bypass Vulnerability
1 rule 1 TTPAn authentication bypass vulnerability exists in Palo Alto Networks PAN-OS GlobalProtect portal and gateway (CVE-2026-0257) when authentication override cookies are enabled, allowing an attacker to establish an unauthorized VPN connection.
CVE-2026-0265 PAN-OS Authentication Bypass with Cloud Authentication Service (CAS)
2 rules 1 TTPCVE-2026-0265 is an authentication bypass vulnerability in Palo Alto Networks PAN-OS when Cloud Authentication Service (CAS) is enabled, allowing an unauthenticated attacker with network access to bypass authentication controls, impacting confidentiality, integrity, and availability.
CVE-2026-0261 PAN-OS Authenticated Admin Command Injection Vulnerability
2 rules 1 TTPCVE-2026-0261 describes multiple command injection vulnerabilities in Palo Alto Networks PAN-OS software that allow an authenticated administrator to bypass system restrictions and execute arbitrary commands as root.
CVE-2026-0258 PAN-OS SSRF vulnerability in IKEv2 certificate URL fetching
2 rules 1 TTPCVE-2026-0258 is a medium severity server-side request forgery (SSRF) vulnerability in Palo Alto Networks PAN-OS that allows an unauthenticated attacker to cause the firewall to send network requests to unintended destinations, potentially leading to a denial of service (DoS).
CVE-2026-0262 PAN-OS: Denial of Service Vulnerabilities in Network Traffic Parsing
2 rules 2 TTPsUnauthenticated attackers can cause a denial of service (DoS) condition on Palo Alto Networks PAN-OS firewalls by sending specially crafted network traffic, as described in CVE-2026-0262.
PAN-OS Authentication Portal Remote Code Execution Vulnerability
2 rules 1 TTPAn unauthenticated remote code execution vulnerability exists in the PAN-OS Authentication Portal (Captive Portal) service, potentially allowing attackers to execute arbitrary code with root privileges on PA-Series and VM-Series firewalls by sending crafted network packets.
Palo Alto Networks PAN-OS Out-of-bounds Write Vulnerability Added to CISA KEV Catalog
3 rules 1 TTPCVE-2026-0300, a Palo Alto Networks PAN-OS out-of-bounds write vulnerability, has been added to CISA's Known Exploited Vulnerabilities Catalog due to evidence of active exploitation.