Triage queue
// Operations

Legacy TLS negotiated on the perimeter

Inbound connection negotiated TLS 1.0. Retained as compliance evidence; not indicative of compromise.

ALT-9A3E1ELowFalse positive
12Low

Why this fired

Rule: Bulk data egress

Any event where eventType is DATA_EGRESS

A transfer far larger than the baseline for the host, to a destination not previously seen. The shape of exfiltration rather than backup.

Triggering event

The exact record that satisfied the rule.

Tls NegotiationLow2026-09-04 08:15:29ZPalo Alto Edge
TLS 1.0 negotiated on inbound connection to 10.4.12.9:443 (cipher TLS_RSA_WITH_AES_128_CBC_SHA)

What else was happening

No principal on this event, so there is nothing to correlate on.

Nothing nearby

No other events for this principal in the surrounding hour.

Alert

Raised
8d ago
Last updated
7d ago
Risk score
12
Source
Palo Alto Edge
Detected by
Correlation rule

Pivot

Same rule

1 other recent alert(s)