Triage queue
// Operations

1.2 GB transferred to an unrecognised destination

Sustained egress to 104.28.211.19, an address with no traffic in the previous thirty days.

ALT-70BAD5MediumResolved
55Moderate

This alert has been escalated. Open the incident to see the full case.

Why this fired

Rule: Bulk data egress

Any event where eventType is DATA_EGRESS

A transfer far larger than the baseline for the host, to a destination not previously seen. The shape of exfiltration rather than backup.

Triggering event

The exact record that satisfied the rule.

Data EgressMedium2026-09-03 13:37:29ZPalo Alto Edge
allow tcp 10.4.12.28:49881 -> 104.28.211.19:443 bytes_out=1284739584 sni="upload.filetransfer.example" — destination unseen in prior 30 days

What else was happening

Other activity for hlindqvist in the surrounding hour.

TimeEventSeverityHost
2026-09-03 13:15:29ZFile ReadInfoWIN-FS02
2026-09-03 13:15:38ZFile ReadInfoWIN-FS02
2026-09-03 13:15:47ZFile ReadInfoWIN-FS02
2026-09-03 13:15:56ZFile ReadInfoWIN-FS02
2026-09-03 13:16:05ZFile ReadInfoWIN-FS02
2026-09-03 13:16:14ZFile ReadInfoWIN-FS02
2026-09-03 13:16:23ZFile ReadInfoWIN-FS02
2026-09-03 13:16:32ZFile ReadInfoWIN-FS02
2026-09-03 13:16:41ZFile ReadInfoWIN-FS02
2026-09-03 13:16:50ZFile ReadInfoWIN-FS02
2026-09-03 13:16:59ZFile ReadInfoWIN-FS02
2026-09-03 13:17:08ZFile ReadInfoWIN-FS02
2026-09-03 13:17:17ZFile ReadInfoWIN-FS02
2026-09-03 13:17:26ZFile ReadInfoWIN-FS02
2026-09-03 13:17:35ZFile ReadInfoWIN-FS02
2026-09-03 13:17:44ZFile ReadInfoWIN-FS02
2026-09-03 13:17:53ZFile ReadInfoWIN-FS02
2026-09-03 13:18:02ZFile ReadInfoWIN-FS02
2026-09-03 13:18:11ZFile ReadInfoWIN-FS02
2026-09-03 13:18:20ZFile ReadInfoWIN-FS02

Alert

Raised
9d ago
Last updated
7d ago
Risk score
55
Source
Palo Alto Edge
Detected by
Correlation rule

Entity risk

22Guarded

hlindqvist carries a standing risk score derived from all of its activity, not just this alert.

Open the entity profile

Pivot

Same rule

1 other recent alert(s)