Advanced Threat Prevention Dashboard: Hosts Generating Cloud Detected C2 Traffic
Focus
Focus
Strata Cloud Manager

Advanced Threat Prevention Dashboard: Hosts Generating Cloud Detected C2 Traffic

Table of Contents

Advanced Threat Prevention Dashboard: Hosts Generating Cloud Detected C2 Traffic

Examine the source IPs and users responsible for generating command and control (C2) traffic.
Where Can I Use This?What Do I Need?
  • Prisma Access
    (with Strata Cloud Manager or Panorama configuration management)
  • NGFWs
    (with Strata Cloud Manager or Panorama configuration management)
  • Each of these licenses include access to Strata Cloud Manager:
    • Prisma Access
    • AIOps for NGFW Free (use the AIOps for NGFW Free app) or AIOps for NGFW Premium license (use the Strata Cloud Manager app)
  • Threat Prevention or Advanced Threat Prevention license
  • (for VM-Series software NGFWs)
  • A role that has permission to view the dashboard
  • Click Strata Cloud ManagerDashboardsMore DashboardsAdvanced Threat Prevention to view the dashboard.
Examine the source IPs and users responsible for generating command and control (C2) traffic. Advanced Threat Prevention uses cloud-based engines and inline cloud analysis to detect and analyze traffic for unknown C2 and vulnerabilities. Click the search icon next to the source IP to review the usage patterns related to the source IP. A contextual link to Log Viewer helps to analyze the threat sessions, download the packet capture and cloud report to get additional context and leverage Palo Alto Networks threat analytics data and improve your incident response processes.