Get a holistic view of threat activity and various types of threats seen in your
Prisma Access and NGFW environments.
| Where Can I Use This? | What Do I Need? |
|
| You must have at least one of these licenses to use the Activity
Insights:The other licenses needed to view the Activity Insights:Threats
tab are:- Strata Logging Service
- CDSS licenses
- ADEM Observability will unlock additional
Prisma Access features
|
The Activity Insights: Threats dashboard in Strata Cloud Manager provides a
comprehensive visualization of the threats detected and blocked across your network.
By aggregating data from your NGFWs and security subscriptions (Prisma Access, NGFW,
Prisma SD-WAN, and standalone resolver (
Advanced DNS Security Resolver))
deployments, this dashboard helps you quantify the specific value of your security
investments and understand the nature of attacks targeting your organization.
Standard security controls often blend different types of detections, making it
difficult to distinguish between known commodity threats and sophisticated, emerging
attacks. The Activity Insights: Threats dashboard addresses this by distinguishing
between standard signature-based blocks and novel attacks identified by Palo Alto
Networks Advanced CDSS (cloud-delivered security services) subscriptions.
The threats dashboard defines threats into
nine core threat categories
that pulls in threat concepts from Advanced Threat Prevention, Advanced DNS
Security, Advanced WildFire, and Advanced URL Filtering into a single pane.
Each of these core categories include various
threat sub-categories which
provide specific, granular classifications used to identify advanced emerging
threats or new and unknown threats. These sub-categories represent threats that are
specifically detected by Palo Alto Networks advanced subscriptions utilizing
PrecisionAI in the cloud, such as Cobalt Strike C2
detected by Advanced Threat Prevention or hijacked domains detected by Advanced DNS
Security. These sub-categories allows security teams to clearly map threats to
specific security controls, facilitate accurate risk reporting, and ensure strict
adherence to established industry frameworks.
Threat activity presented in Activity Insights can take up to 30 minutes to
populate after logs are forwarded to the
Strata Logging service.
Palo Alto Networks CDSS products classify security threats into these logical
categories to help you understand the threat landscape and create effective security
policies. Threats fall into several major categories that are further categorized
with increased specificity based on traffic patterns associated with the malicious
activity of a subscription type. By organizing threats into these categories, Palo
Alto Networks products enable you to detect, classify, and respond to threats more
effectively, whether you're configuring policies, investigating incidents, or
monitoring your security posture across your environment.
Threat Categories and corresponding threat subcategories are applicable only
to Strata Cloud Manager based dashboards that are populated using data from
Strata Logging service. For PAN-OS
based threat log categories, refer to:
Threat Signature Categories.
Dashboard Widgets and Metrics
The dashboard provides two views, accessible through the
Threat | CVE toggle at the top of
the page. The Threat view displays threat activity organized
by threat categories and subscriptions, while the CVE view
provides visibility into CVE exploits detected in your network by Advanced Threat
Prevention.
Activity Insights: Threats includes several key views to help
you assess your security posture and threat landscape, at a glance. Depending on how
you filter your selections, the trend lines correlate with the final actions taken
to defend your network from malicious threats.
Threat View Selector
By default, the dashboard displays total threats. You can switch between
total threats, new and unknown threats, or platform effects based on
threats processed from the environments listed in the
Scope
Selection. Refer to
Activity Insights: Overview for
details on the
Scope Selection options.
Threats: Displays the aggregate number of threats detected
over a selected time period (such as the last 24 hours, 7 days, or
30 days [based on the selected filters]), helping you understand the
overall threat prevalence in your network deployment. You can also
filter based on an available Advanced Security Subscription, through
the filter selection at the top of the dashboard (Threat
License) or in the widget.
New & Unknown: Displays the novel and highly sophisticated
attacks detected by cloud-based machine learning and dynamic
analysis. This category highlights the specific value of services
like Advanced Threat Prevention and Advanced WildFire in stopping
patient zero attacks that lack pre-existing signatures. You can
also filter based on an available Advanced Security Subscription,
through the filter selection at the top of the dashboard
(Threat License) or in the widget.
Platform Effects: Displays the number of threats prevented
in your environment as a direct result of participating in the Palo
Alto Networks global security ecosystem. Platform effects quantify
the compound protection you receive beyond your own traffic
analysis, broken down into two categories:
Global Customer Intel Sharing—Attacks prevented based
on prior attacks found in other customer networks. When a
threat is detected in any Palo Alto Networks customer
environment, the resulting intelligence (signatures,
verdicts, and indicators) is distributed globally,
protecting your network from that threat before you
encounter it directly.
Security Services Intel Sharing—Additional attack
kill chain stages stopped due to intelligence sharing
between security services. When one Advanced CDSS
subscription (such as Advanced WildFire) generates a
detection, that intelligence enriches other subscriptions
(such as Advanced URL Filtering or Advanced DNS Security),
blocking subsequent stages of the same attack across
different vectors.
Filters
The Threat view supports the following filters from the filter bar:
Time Range—The time window for threat activity (for
example, last 24 hours, 7 days, or 30 days).
Scope Selection—The environments included in the
threat analysis (for example, Prisma Access, NGFW deployments). Refer to
Activity Insights: Overview for
details on the
Scope Selection options.
Subtenant—Filter by a specific subtenant to view
threat activity scoped to a particular tenant environment.
Threat License—Filter by a specific Advanced Security
subscription (Advanced Threat Prevention, Advanced URL Filtering, Advanced
DNS Security, or Advanced WildFire) to view threats detected by that
service, or choose ALL to display threats across all
subscriptions.
Category & Subcategory—Filter by threat category
or subcategory to focus on specific attack types.
Dashboard Widgets
Threat Categories: Breaks down detections by type, such as Malware,
Phishing, and Command and Control (C2). This segmentation helps you identify
which specific attack vectors are most active in your network. The available
Threat Categories shown are based on the initial
filter selection of Threats or New &
Unknown.
Sub-Categories by Type: Details specific attack vectors detected by
advanced subscriptions, distinguishing unique attacks like "Breach Tool
Randomized Callbacks" or "Advanced Data Exfiltration" from standard
traffic.
Actions Taken by Type: Toggle between
Blocked Threats and Alerted
Threats to view the aggregate count for each action type.
Below the count, a severity breakdown displays the distribution across
Critical, High, Medium, Low, and
Informational levels, allowing you to quickly identify whether
high-severity threats are being blocked or only alerted.
To maintain a robust security posture, administrators should consider
ensuring that security policy rules transition from detection to active
enforcement. A high frequency of Alert actions,
particularly for threats classified as Critical
or High severity, indicates a security gap where
malicious activity is identified but not prevented. By systematically
reviewing these logs and updating policy actions to
Drop or Reset, you can
mitigate risks such as remote code execution and command-and-control
(C2) traffic in real-time, preventing potential compromises before they
impact the network.
Cloud-Delivered Security Services (CDSS) subscriptions provide the
granular intelligence necessary to automate this enforcement across
various attack vectors. When analyzing your threat posture, evaluate the
efficacy of your current Security Profiles—including Advanced Threat
Prevention, Advanced URL Filtering, and Advanced DNS Security—and refine
them to block specific threat categories that currently trigger alerts.
Utilizing the
Policy Optimizer,
Policy Analyzer, and
implementing Palo Alto Networks Best Practice Profiles further
streamlines this process, allowing for the replacement of
over-provisioned rules with high-fidelity enforcement that dynamically
adapts to the evolving threat landscape.
Palo Alto Networks recommends reviewing the following resources:
Insights and Investigation
Depending on the filter selections made for the widgets, the right-pane displays a
brief description of the selected
Threat Category or
Threat Subcategory and provides up to 6 related articles
developed by
Palo Alto Networks .
You can perform the following tasks:
View Article Details—Provides a brief description about the recommended
article. Select View Details to open a new window
referencing the Unit 42 research article that details the threat.
Learn more About the Selected Threat Category—Provides a brief description of
the selected threat type. Select Learn more for more
details about the Threat Category or Threat Sub-category.
Threat Detail and Investigation
You can interact with dashboard elements to redefine the entries that are displayed
in the Threat Detail view. This interface provides granular context for
individual incidents to support rapid triage and investigation.
From the detailed threat threats view, you can perform the following tasks:
Impact Assessment—View the number of affected sessions, unique users,
applications, and specific devices where the threat was detected.
Evidence and Classification—Review the threat ID, severity,
description, and the specific security subscription that identified the
malicious activity (for example, Advanced DNS Security or Advanced URL
Filtering).
Log Correlation—Pivot directly to the
Log Viewer to examine the
specific logs associated with the detected threat for deeper forensic
analysis.
Campaign Association—Identify if a specific threat is part of a larger
known campaign or associated with specific threat actors, allowing you to
prioritize resources based on the severity of the potential breach.
Review the following details of unique threats in your network.
Severity—The threat severity is determined
based on how easy it is to exploit the vulnerability, the impact on
vulnerability, the pervasiveness of the vulnerable product, the impact of
the vulnerability, and more. The severity is categorized as:
- Critical—When vulnerability affects default installations
of very widely deployed software and the exploits can result in root
compromised. The exploit code (information about how to exploit the
system code, methods, proof of concept (POC)) is widely available
and easy to exploit. The attacker doesn't need any special
authentication credentials, or knowledge about individual
victims.
- High—Threats that have the ability to become critical but
have mitigating factors; for example, they may be difficult to
exploit, do not result in elevated privileges, or do not have a
large victim pool.
- Medium—Minor threats in which impact is minimized, such as
DoS attacks that do not compromise the target or exploits that
require an attacker to reside on the same LAN as the victim, affect
only non-standard configurations or obscure applications, or provide
very limited access.
- Low—Warning-level threats that have very little impact on
an organization's infrastructure. They usually require local or
physical system access and may often result in victim privacy or DoS
issues and information leakage.
- Informational—Suspicious events that do not pose an
immediate threat, but that are reported to call attention to deeper
problems that could possibly exist.
Threat Name—Threat signature name. Clicking
on an Threat signature name automatically performs a
Threat Search using the SHA-256
hash value associated with the threat.
Total by Actions—Displays the actions taken,
either blocked or alerted, based on your security policy settings.
Users—The number of users exposed to the
threat.
Applications—The number of distinct types of
software or services (App-IDs) that were identified as the vehicle for the
threat.
Devices—The number of devices that were
involved in the activity related to that specific threat signature.
Category—The core threat category
that aligns with the detected threat.
Sub Category—The threat sub-category
that corresponds with the specific Advanced service used to detect the
threat.
Threat ID—Unique threat signature ID. Use
the threat ID to look up the latest information that the Palo Alto Networks
threat database has for this signature. Clicking on an threat ID value
automatically performs a
Threat Search. Alternatively, you
can also refer to
Palo Alto Networks Threat Vault
for threat ID details.
Rule Name—The specific Security Policy rule
that the traffic matched against before the threat was detected.
Sessions—The number of sessions where the
threat was detected. Click the threat name to view all related threat
sessions in the specified time range. The threat session table provides
context on the threat such as time when the Palo Alto Network security
services detected the threats, users, rules, applications, devices impacted
by the threat, and action taken (allowed or blocked) on the threat.
Actions—Log history of the threat in the
Log
Viewer to aid in threat investigations.
CVE Insights
Select the CVE toggle to view CVE exploits detected in your
network by Advanced Threat Prevention. The CVE view displays the total number of
unique CVEs detected across your environment in the selected time range, the total
number of threat occurrences associated with those CVEs, and a radial chart mapping
CVE exploits to their corresponding threat categories. Select a category in the
chart to filter the detail table below.
The CVE view supports the following filters from the filter bar:
Time Range—The time window for CVE exploit activity
(for example, last 24 hours, 7 days, or 30 days).
Scope Selection—The environments included in the CVE
analysis (for example, Prisma Access, NGFW deployments). Refer to
Activity Insights: Overview for
details on the
Scope Selection options.
CVSS Score—Filter by Common Vulnerability Scoring
System score to focus on CVEs within a specific severity range (0.0–10.0).
Higher scores indicate more severe vulnerabilities.
EPSS Score—Filter by the Exploit Prediction Scoring
System probability (0–1) that a CVE will be exploited in the wild within the
next 30 days.
EPSS Percentile—Filter by the relative ranking of a
CVE compared to all other scored vulnerabilities. A higher percentile
indicates a greater likelihood of exploitation relative to other CVEs.
ATP Threat Severity—Filter by the threat severity
level assigned by Advanced Threat Prevention to the exploit signatures
associated with a CVE (Critical, High, Medium, Low, or
Informational).
Threat Action—Filter by the enforcement action taken
on the detected CVE exploit (blocked or alerted) based on your security
policy settings.
Source IP Address—Filter by the source IP address of
the traffic that triggered the CVE exploit detection.
Destination IP Address—Filter by the destination IP
address of the traffic targeted by the CVE exploit.
Category & Subcategory—Filter by threat category
or subcategory to focus on CVEs associated with specific attack types.
CVE Detail Table
The detail table at the bottom of the CVE view provides two tabs:
The CVEs tab displays the following columns:
CVE ID—The unique identifier for the CVE (for
example, CVE-2024-1234). Clicking on a CVE ID automatically performs a
Threat Search using the CVE
identifier.
Severity—The threat severity level associated with the
CVE exploit detection.
CVSS Score—The Common Vulnerability Scoring System
score indicating the overall severity of the vulnerability.
Threat ID—The threat signature IDs that map to this
CVE. One CVE can map to multiple threat IDs, indicated by a "+N" count
next to the primary ID. You can expand the row to reveal child rows
showing details for each associated threat ID, including the threat name,
threat severity, sub-type, associated applications, total by actions, and
a link to view the corresponding log entries.
Type—The type of vulnerability (for example,
vulnerability, exploit).
Affected Devices—The number of endpoint devices
affected by the CVE exploit activity. This column is only available with
both Advanced Threat Prevention and Device Security subscriptions.
Priority—A prioritization metric to help you
determine which CVEs require immediate patching attention. This column is
only available with both Advanced Threat Prevention and Device Security
subscriptions.
Total by Actions—The number of occurrences broken down
by action taken (blocked or alerted) based on your security policy
settings.
EPSS Percentile—The Exploit Prediction Scoring System
percentile ranking, indicating the relative likelihood of exploitation
compared to all other CVEs.
EPSS Score—The probability (0–1) that the
vulnerability will be exploited in the wild within the next 30 days.
Exploit Status—Indicates whether a known exploit
exists in the wild for this CVE.