Triage queue
// Operations
Legacy TLS negotiated on the perimeter
Inbound connection negotiated TLS 1.0. Retained as compliance evidence; not indicative of compromise.
ALT-9A3E1ELowFalse positive
12Low
Why this fired
Rule: Bulk data egress
Any event where eventType is DATA_EGRESS
A transfer far larger than the baseline for the host, to a destination not previously seen. The shape of exfiltration rather than backup.
Triggering event
The exact record that satisfied the rule.
Tls NegotiationLow2026-09-04 08:15:29ZPalo Alto Edge
TLS 1.0 negotiated on inbound connection to 10.4.12.9:443 (cipher TLS_RSA_WITH_AES_128_CBC_SHA)
What else was happening
No principal on this event, so there is nothing to correlate on.
Nothing nearby
No other events for this principal in the surrounding hour.
Alert
- Raised
- 8d ago
- Last updated
- 7d ago
- Risk score
- 12
- Source
- Palo Alto Edge
- Detected by
- Correlation rule
Pivot
Same rule
1 other recent alert(s)