Managed Sentinel – Alert 236
|Alert Name||Access to potentially malicious URLs|
|Description||This alert identifies connections to potentially malicious URL|
|Threat Indicator||Compromised Host|
|MITRE ATT&CK Tactics||Priviledge Escalation|
|Log sources||URL Filtering|
|False Positive||Browsers Adware|
Incorrect Threat Intelligence feed
|Recommendations||1. Investigate the type of traffic allowed to the malicious IP address |
2. Manually perform a validation of the malicious IP address on external Threat Intell sources (e.g www.abuseIPdb.com).
3. Identify the number of requests within a specific period of time which could be an solid indicator of a compromised host.
4. Perform a AV/AM scan for the affected internal machine
5. Complete a Sentinel investigation for the same entity (IP address or user account) to understand if any other lateral attacks were completed