Activity Insights: Threats
Focus
Strata Cloud Manager

Activity Insights: Threats

Table of Contents

Activity Insights: Threats

Get a holistic view of threat activity and various types of threats seen in your Prisma Access and NGFW environments.
Where Can I Use This?What Do I Need?
  • Prisma Access
    (with Strata Cloud Manager or Panorama configuration management)
  • NGFWs
    (with Strata Cloud Manager or Panorama configuration management)
You must have at least one of these licenses to use the Activity Insights:The other licenses needed to view the Activity Insights:Threats tab are:
  • Strata Logging Service
  • CDSS licenses
  • ADEM Observability will unlock additional Prisma Access features
The Activity Insights: Threats dashboard in Strata Cloud Manager provides a comprehensive visualization of the threats detected and blocked across your network. By aggregating data from your NGFWs and security subscriptions (Prisma Access, NGFW, Prisma SD-WAN, and standalone resolver (Advanced DNS Security Resolver)) deployments, this dashboard helps you quantify the specific value of your security investments and understand the nature of attacks targeting your organization.
Standard security controls often blend different types of detections, making it difficult to distinguish between known commodity threats and sophisticated, emerging attacks. The Activity Insights: Threats dashboard addresses this by distinguishing between standard signature-based blocks and novel attacks identified by Palo Alto Networks Advanced CDSS (cloud-delivered security services) subscriptions.
The threats dashboard defines threats into nine core threat categories that pulls in threat concepts from Advanced Threat Prevention, Advanced DNS Security, Advanced WildFire, and Advanced URL Filtering into a single pane.
Each of these core categories include various threat sub-categories which provide specific, granular classifications used to identify advanced emerging threats or new and unknown threats. These sub-categories represent threats that are specifically detected by Palo Alto Networks advanced subscriptions utilizing PrecisionAI in the cloud, such as Cobalt Strike C2 detected by Advanced Threat Prevention or hijacked domains detected by Advanced DNS Security. These sub-categories allows security teams to clearly map threats to specific security controls, facilitate accurate risk reporting, and ensure strict adherence to established industry frameworks.
Threat activity presented in Activity Insights can take up to 30 minutes to populate after logs are forwarded to the Strata Logging service.
Palo Alto Networks CDSS products classify security threats into these logical categories to help you understand the threat landscape and create effective security policies. Threats fall into several major categories that are further categorized with increased specificity based on traffic patterns associated with the malicious activity of a subscription type. By organizing threats into these categories, Palo Alto Networks products enable you to detect, classify, and respond to threats more effectively, whether you're configuring policies, investigating incidents, or monitoring your security posture across your environment.
Threat Categories and corresponding threat subcategories are applicable only to Strata Cloud Manager based dashboards that are populated using data from Strata Logging service. For PAN-OS based threat log categories, refer to: Threat Signature Categories.
Dashboard Widgets and Metrics
The dashboard provides two views, accessible through the Threat | CVE toggle at the top of the page. The Threat view displays threat activity organized by threat categories and subscriptions, while the CVE view provides visibility into CVE exploits detected in your network by Advanced Threat Prevention.
Activity Insights: Threats includes several key views to help you assess your security posture and threat landscape, at a glance. Depending on how you filter your selections, the trend lines correlate with the final actions taken to defend your network from malicious threats.
Threat View Selector
By default, the dashboard displays total threats. You can switch between total threats, new and unknown threats, or platform effects based on threats processed from the environments listed in the Scope Selection. Refer to Activity Insights: Overview for details on the Scope Selection options.
  • Threats: Displays the aggregate number of threats detected over a selected time period (such as the last 24 hours, 7 days, or 30 days [based on the selected filters]), helping you understand the overall threat prevalence in your network deployment. You can also filter based on an available Advanced Security Subscription, through the filter selection at the top of the dashboard (Threat License) or in the widget.
  • New & Unknown: Displays the novel and highly sophisticated attacks detected by cloud-based machine learning and dynamic analysis. This category highlights the specific value of services like Advanced Threat Prevention and Advanced WildFire in stopping patient zero attacks that lack pre-existing signatures. You can also filter based on an available Advanced Security Subscription, through the filter selection at the top of the dashboard (Threat License) or in the widget.
  • Platform Effects: Displays the number of threats prevented in your environment as a direct result of participating in the Palo Alto Networks global security ecosystem. Platform effects quantify the compound protection you receive beyond your own traffic analysis, broken down into two categories:
    • Global Customer Intel Sharing—Attacks prevented based on prior attacks found in other customer networks. When a threat is detected in any Palo Alto Networks customer environment, the resulting intelligence (signatures, verdicts, and indicators) is distributed globally, protecting your network from that threat before you encounter it directly.
    • Security Services Intel Sharing—Additional attack kill chain stages stopped due to intelligence sharing between security services. When one Advanced CDSS subscription (such as Advanced WildFire) generates a detection, that intelligence enriches other subscriptions (such as Advanced URL Filtering or Advanced DNS Security), blocking subsequent stages of the same attack across different vectors.
Filters
The Threat view supports the following filters from the filter bar:
  • Time Range—The time window for threat activity (for example, last 24 hours, 7 days, or 30 days).
  • Scope Selection—The environments included in the threat analysis (for example, Prisma Access, NGFW deployments). Refer to Activity Insights: Overview for details on the Scope Selection options.
  • Subtenant—Filter by a specific subtenant to view threat activity scoped to a particular tenant environment.
  • Threat License—Filter by a specific Advanced Security subscription (Advanced Threat Prevention, Advanced URL Filtering, Advanced DNS Security, or Advanced WildFire) to view threats detected by that service, or choose ALL to display threats across all subscriptions.
  • Category & Subcategory—Filter by threat category or subcategory to focus on specific attack types.
Dashboard Widgets
  • Threat Categories: Breaks down detections by type, such as Malware, Phishing, and Command and Control (C2). This segmentation helps you identify which specific attack vectors are most active in your network. The available Threat Categories shown are based on the initial filter selection of Threats or New & Unknown.
  • Sub-Categories by Type: Details specific attack vectors detected by advanced subscriptions, distinguishing unique attacks like "Breach Tool Randomized Callbacks" or "Advanced Data Exfiltration" from standard traffic.
  • Actions Taken by Type: Toggle between Blocked Threats and Alerted Threats to view the aggregate count for each action type. Below the count, a severity breakdown displays the distribution across Critical, High, Medium, Low, and Informational levels, allowing you to quickly identify whether high-severity threats are being blocked or only alerted.
    To maintain a robust security posture, administrators should consider ensuring that security policy rules transition from detection to active enforcement. A high frequency of Alert actions, particularly for threats classified as Critical or High severity, indicates a security gap where malicious activity is identified but not prevented. By systematically reviewing these logs and updating policy actions to Drop or Reset, you can mitigate risks such as remote code execution and command-and-control (C2) traffic in real-time, preventing potential compromises before they impact the network.
    Cloud-Delivered Security Services (CDSS) subscriptions provide the granular intelligence necessary to automate this enforcement across various attack vectors. When analyzing your threat posture, evaluate the efficacy of your current Security Profiles—including Advanced Threat Prevention, Advanced URL Filtering, and Advanced DNS Security—and refine them to block specific threat categories that currently trigger alerts. Utilizing the Policy Optimizer, Policy Analyzer, and implementing Palo Alto Networks Best Practice Profiles further streamlines this process, allowing for the replacement of over-provisioned rules with high-fidelity enforcement that dynamically adapts to the evolving threat landscape.
    Palo Alto Networks recommends reviewing the following resources:
Insights and Investigation
Depending on the filter selections made for the widgets, the right-pane displays a brief description of the selected Threat Category or Threat Subcategory and provides up to 6 related articles developed by Palo Alto Networks .
You can perform the following tasks:
  • View Article Details—Provides a brief description about the recommended article. Select View Details to open a new window referencing the Unit 42 research article that details the threat.
  • Learn more About the Selected Threat Category—Provides a brief description of the selected threat type. Select Learn more for more details about the Threat Category or Threat Sub-category.
Threat Detail and Investigation
You can interact with dashboard elements to redefine the entries that are displayed in the Threat Detail view. This interface provides granular context for individual incidents to support rapid triage and investigation.
From the detailed threat threats view, you can perform the following tasks:
  • Impact Assessment—View the number of affected sessions, unique users, applications, and specific devices where the threat was detected.
  • Evidence and Classification—Review the threat ID, severity, description, and the specific security subscription that identified the malicious activity (for example, Advanced DNS Security or Advanced URL Filtering).
  • Log Correlation—Pivot directly to the Log Viewer to examine the specific logs associated with the detected threat for deeper forensic analysis.
  • Campaign Association—Identify if a specific threat is part of a larger known campaign or associated with specific threat actors, allowing you to prioritize resources based on the severity of the potential breach.
Review the following details of unique threats in your network.
  • Severity—The threat severity is determined based on how easy it is to exploit the vulnerability, the impact on vulnerability, the pervasiveness of the vulnerable product, the impact of the vulnerability, and more. The severity is categorized as:
    • Critical—When vulnerability affects default installations of very widely deployed software and the exploits can result in root compromised. The exploit code (information about how to exploit the system code, methods, proof of concept (POC)) is widely available and easy to exploit. The attacker doesn't need any special authentication credentials, or knowledge about individual victims.
    • High—Threats that have the ability to become critical but have mitigating factors; for example, they may be difficult to exploit, do not result in elevated privileges, or do not have a large victim pool.
    • Medium—Minor threats in which impact is minimized, such as DoS attacks that do not compromise the target or exploits that require an attacker to reside on the same LAN as the victim, affect only non-standard configurations or obscure applications, or provide very limited access.
    • Low—Warning-level threats that have very little impact on an organization's infrastructure. They usually require local or physical system access and may often result in victim privacy or DoS issues and information leakage.
    • Informational—Suspicious events that do not pose an immediate threat, but that are reported to call attention to deeper problems that could possibly exist.
  • Threat Name—Threat signature name. Clicking on an Threat signature name automatically performs a Threat Search using the SHA-256 hash value associated with the threat.
  • Total by Actions—Displays the actions taken, either blocked or alerted, based on your security policy settings.
  • Users—The number of users exposed to the threat.
  • Applications—The number of distinct types of software or services (App-IDs) that were identified as the vehicle for the threat.
  • Devices—The number of devices that were involved in the activity related to that specific threat signature.
  • Category—The core threat category that aligns with the detected threat.
  • Sub Category—The threat sub-category that corresponds with the specific Advanced service used to detect the threat.
  • License—The Palo Alto Networks security services that detected the threat.
  • Threat ID—Unique threat signature ID. Use the threat ID to look up the latest information that the Palo Alto Networks threat database has for this signature. Clicking on an threat ID value automatically performs a Threat Search. Alternatively, you can also refer to Palo Alto Networks Threat Vault for threat ID details.
  • Rule Name—The specific Security Policy rule that the traffic matched against before the threat was detected.
  • Sessions—The number of sessions where the threat was detected. Click the threat name to view all related threat sessions in the specified time range. The threat session table provides context on the threat such as time when the Palo Alto Network security services detected the threats, users, rules, applications, devices impacted by the threat, and action taken (allowed or blocked) on the threat.
  • Actions—Log history of the threat in the Log Viewer to aid in threat investigations.
CVE Insights
Select the CVE toggle to view CVE exploits detected in your network by Advanced Threat Prevention. The CVE view displays the total number of unique CVEs detected across your environment in the selected time range, the total number of threat occurrences associated with those CVEs, and a radial chart mapping CVE exploits to their corresponding threat categories. Select a category in the chart to filter the detail table below.
The CVE view supports the following filters from the filter bar:
  • Time Range—The time window for CVE exploit activity (for example, last 24 hours, 7 days, or 30 days).
  • Scope Selection—The environments included in the CVE analysis (for example, Prisma Access, NGFW deployments). Refer to Activity Insights: Overview for details on the Scope Selection options.
  • CVSS Score—Filter by Common Vulnerability Scoring System score to focus on CVEs within a specific severity range (0.0–10.0). Higher scores indicate more severe vulnerabilities.
  • EPSS Score—Filter by the Exploit Prediction Scoring System probability (0–1) that a CVE will be exploited in the wild within the next 30 days.
  • EPSS Percentile—Filter by the relative ranking of a CVE compared to all other scored vulnerabilities. A higher percentile indicates a greater likelihood of exploitation relative to other CVEs.
  • ATP Threat Severity—Filter by the threat severity level assigned by Advanced Threat Prevention to the exploit signatures associated with a CVE (Critical, High, Medium, Low, or Informational).
  • Threat Action—Filter by the enforcement action taken on the detected CVE exploit (blocked or alerted) based on your security policy settings.
  • Source IP Address—Filter by the source IP address of the traffic that triggered the CVE exploit detection.
  • Destination IP Address—Filter by the destination IP address of the traffic targeted by the CVE exploit.
  • Category & Subcategory—Filter by threat category or subcategory to focus on CVEs associated with specific attack types.
CVE Detail Table
The detail table at the bottom of the CVE view provides two tabs:
  • CVEs—Lists unique CVEs detected in your environment with associated metrics.
  • Related Threats—Lists individual threat signatures associated with the detected CVEs.
The CVEs tab displays the following columns:
  • CVE ID—The unique identifier for the CVE (for example, CVE-2024-1234). Clicking on a CVE ID automatically performs a Threat Search using the CVE identifier.
  • Severity—The threat severity level associated with the CVE exploit detection.
  • CVSS Score—The Common Vulnerability Scoring System score indicating the overall severity of the vulnerability.
  • Threat ID—The threat signature IDs that map to this CVE. One CVE can map to multiple threat IDs, indicated by a "+N" count next to the primary ID. You can expand the row to reveal child rows showing details for each associated threat ID, including the threat name, threat severity, sub-type, associated applications, total by actions, and a link to view the corresponding log entries.
  • Type—The type of vulnerability (for example, vulnerability, exploit).
  • Affected Devices—The number of endpoint devices affected by the CVE exploit activity. This column is only available with both Advanced Threat Prevention and Device Security subscriptions.
  • Priority—A prioritization metric to help you determine which CVEs require immediate patching attention. This column is only available with both Advanced Threat Prevention and Device Security subscriptions.
  • Total by Actions—The number of occurrences broken down by action taken (blocked or alerted) based on your security policy settings.
  • EPSS Percentile—The Exploit Prediction Scoring System percentile ranking, indicating the relative likelihood of exploitation compared to all other CVEs.
  • EPSS Score—The probability (0–1) that the vulnerability will be exploited in the wild within the next 30 days.
  • Exploit Status—Indicates whether a known exploit exists in the wild for this CVE.