* [Blog](https://www.paloaltonetworks.com/blog) * [Palo Alto Networks](https://www.paloaltonetworks.com/blog/corporate/) * [Secure the Future](https://www.paloaltonetworks.com/blog/category/secure-the-future/) * Busted by Cortex XDR: AI ... # Busted by Cortex XDR: AI Catches Former Employee Using Backdoor [](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.paloaltonetworks.com%2Fblog%2F2019%2F12%2Fcortex-busted-by-xdr%2F) [](https://twitter.com/share?text=Busted+by+Cortex+XDR%3A+AI+Catches+Former+Employee+Using+Backdoor&url=https%3A%2F%2Fwww.paloaltonetworks.com%2Fblog%2F2019%2F12%2Fcortex-busted-by-xdr%2F) [](https://www.linkedin.com/shareArticle?mini=true&url=https%3A%2F%2Fwww.paloaltonetworks.com%2Fblog%2F2019%2F12%2Fcortex-busted-by-xdr%2F&title=Busted+by+Cortex+XDR%3A+AI+Catches+Former+Employee+Using+Backdoor&summary=&source=) [](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https://www.paloaltonetworks.com/blog/2019/12/cortex-busted-by-xdr/&ts=markdown) \[\](mailto:?subject=Busted by Cortex XDR: AI Catches Former Employee Using Backdoor) Link copied By [David Szabo](https://www.paloaltonetworks.com/blog/author/david-szabo/?ts=markdown "Posts by David Szabo") Dec 11, 2019 5 minutes [Secure the Future](https://www.paloaltonetworks.com/blog/category/secure-the-future/?ts=markdown) [AI Stories](https://www.paloaltonetworks.com/blog/tag/ai-stories/?ts=markdown) [artificial intelligence](https://www.paloaltonetworks.com/blog/tag/artificial-intelligence/?ts=markdown) [Cortex XDR](https://www.paloaltonetworks.com/blog/tag/cortex-xdr/?ts=markdown) [Machine Learning](https://www.paloaltonetworks.com/blog/tag/machine-learning/?ts=markdown) This post is also available in: [日本語 (Japanese)](https://www.paloaltonetworks.com/blog/2019/12/cortex-busted-by-xdr/?lang=ja "Switch to Japanese(日本語)") **This is based on a true story. "Fred"** **did not depart from his employer with good intent: For years, he kept coming back and exfiltrating the company's intellectual property. The moment of truth came four years later, when the company deployed Cortex XDR.** ![A conceptual illustration of how Cortex XDR by Palo Alto Networks can help companies identify insider threats.](https://www.paloaltonetworks.com/blog/wp-content/uploads/2019/12/XDR.jpg) An IT admin for a large multinational American corporation, Fred had been let go four years prior. Knowing the IT group inside and out, he suspected that his ex-colleagues forgot to disable his VPN account. To test it, he used his VPN credentials from his private computer and surprise: He successfully logged in! He knew his company's network very well. He also knew what he was looking for and where to find it. So, for the next four years, he kept coming back to exfiltrate the latest source code from the company's Git repositories. ## Moving from VPN to Source Repositories via an SSH Tunnel Logging in through VPN, he gained access to the VPN subnet. He now needed to get into a different subnet to access the Git repositories with the latest source code. He knew that an old Windows PC used for testing was still running and could provide a way to get there. Fred accessed the workstation with Microsoft's Remote Desktop and set up a PuTTY SSH tunnel to the Git server. He could now pass Git traffic from one subnet to another using the Windows PC as a proxy. He started to exfiltrate source code from the protected subnet, back to a server he'd set up on the internet. ## AI Wakes Up When [Cortex XDR's](https://www.paloaltonetworks.com/blog/2019/11/cortex-announcing-cortex-xdr-2/?ts=markdown) machine learning (ML) engine was deployed, it was trained on network, cloud and endpoint events for a period of time to establish a baseline and identify the behavioral limits beyond which an alert is raised. As soon as this initial training period was over, Cortex XDR's analytics confidently identified the uncommon tunneling process, declaring that the tunneling and RDP processes were abnormal behavior patterns on this network. Even though this behavior had been happening over the past four years, it was still recognized as suspicious: Cortex XDR's analytics not only compared behavior with past trends of the same entity but also to its peer group (in this case, other workstations). ## Our Obsession with Data Leads to Fewer Alerts for the SOC Cortex XDR also noted that the PC tunneling data between the internal network and a host on the internet was an unmanaged device (i.e., no Traps agent). Machine learning starts with rich context. Our data science team's perspective on the topic is: *"If we don't have enough data for analysis, we run the extra mile to collect it."* So, instead of alerting the SOC team prematurely at this point, Cortex XDR dispatched Pathfinder, its lightweight user-mode agent, to collect more data on the workstation and complete the partial analysis cycle. Not having an agent on the server isn't enough of an excuse to raise a half-baked alert and overload the SOC team with partial results, generating extra manual investigation tasks. Pathfinder swiftly arrived, deployed and performed its data collection on the workstation. It took a snapshot of all running processes, all active incoming and outgoing network sessions, users logged in to the computer and uncommon domains in communication. As it collected data, it streamed the results to [Cortex Data Lake](https://www.paloaltonetworks.com/blog/2019/09/cortex-data-lake/?ts=markdown) for Cortex XDR to finish up its analysis. It didn't take long for the ML engine to raise the flag: * Local process socket usage information showed both internal and external (proxy) open sockets to an uncommon domain. * This proxy detection model compared the process initiating the VPN connection, the tunneling behavior, the destination IP address and over 10 other factors with the rest of the organization, and found the behavior to be suspicious. It was now apparent that the organization was facing a threat. * Cortex XDR issued an alert to the SOC, accompanied by all important details to explain what had been happening. ![This screenshot shows Cortex XDR by Palo Alto Networks](https://www.paloaltonetworks.com/blog/wp-content/uploads/2019/12/image1.png) We heard this story shortly after the organization's SOC received the first alert from their brand-new Cortex XDR proof-of-concept. And that is how this article was born. ## ML and Holistic Thinking Wins Beyond displaying Cortex XDR's ML models that adapt to each customer's environment, this story emphasizes how crucial rich data collection is across the network and endpoint. Cortex XDR's obsession with collecting missing data, combined with its holistic approach of stitching network and endpoint events together for rich context, results in better detection and deeper insight as well as ensures that our customers only see the alerts that matter. **The Cortex Data Science team's pledge to reduce your alert fatigue keeps driving us to create a world where each day is safer and more secure than the one before. Learn more about** [**Cortex XDR**](https://www.paloaltonetworks.com/cortex/cortex-xdr?ts=markdown)**.** *Read more stories in the* [*Busted by Cortex XDR*](https://www.paloaltonetworks.com/blog/tag/ai-stories/?ts=markdown)*series.* *** ** * ** *** ## Related Blogs ### [Secure the Future](https://www.paloaltonetworks.com/blog/category/secure-the-future/?ts=markdown), [Uncategorized](https://www.paloaltonetworks.com/blog/category/uncategorized/?ts=markdown) [#### Busted by Cortex XDR: a True Story of Human Intuition and AI](https://www.paloaltonetworks.com/blog/2020/03/cortex-ai/) ### [Secure the Future](https://www.paloaltonetworks.com/blog/category/secure-the-future/?ts=markdown) [#### Busted by Cortex XDR: Network Traffic Analysis in Action](https://www.paloaltonetworks.com/blog/2020/03/cortex-busted-by-cortex-xdr/) ### [AI and Cybersecurity](https://www.paloaltonetworks.com/blog/security-operations/category/ai-and-cybersecurity/?ts=markdown), [Uncategorized](https://www.paloaltonetworks.com/blog/category/uncategorized/?ts=markdown), [Use-Cases](https://www.paloaltonetworks.com/blog/security-operations/category/use-cases/?ts=markdown) [#### No More Guessing: Accurate AI Security with Palo Alto Networks](https://www.paloaltonetworks.com/blog/security-operations/no-more-guessing-accurate-ai-security-with-palo-alto-networks/) ### [AI and Cybersecurity](https://www.paloaltonetworks.com/blog/security-operations/category/ai-and-cybersecurity/?ts=markdown), [Must-Read Articles](https://www.paloaltonetworks.com/blog/security-operations/category/must-read-articles/?ts=markdown), [Product Features](https://www.paloaltonetworks.com/blog/security-operations/category/product-features/?ts=markdown), [Use-Cases](https://www.paloaltonetworks.com/blog/security-operations/category/use-cases/?ts=markdown) [#### NL2XQL: Turning Natural Language into Powerful Cybersecurity Querying](https://www.paloaltonetworks.com/blog/security-operations/nl2xql-turning-natural-language-into-powerful-cybersecurity-querying/) ### [Must-Read Articles](https://www.paloaltonetworks.com/blog/security-operations/category/must-read-articles/?ts=markdown), [Use-Cases](https://www.paloaltonetworks.com/blog/security-operations/category/use-cases/?ts=markdown) [#### The Role of AI in Reshaping Cybersecurity Careers](https://www.paloaltonetworks.com/blog/security-operations/the-role-of-ai-in-reshaping-cybersecurity-careers/) ### [Must-Read Articles](https://www.paloaltonetworks.com/blog/security-operations/category/must-read-articles/?ts=markdown), [Use-Cases](https://www.paloaltonetworks.com/blog/security-operations/category/use-cases/?ts=markdown) [#### Battling macOS Malware with Cortex AI](https://www.paloaltonetworks.com/blog/security-operations/battling-macos-malware-with-cortex-ai/) ### Subscribe to the Blog! Sign up to receive must-read articles, Playbooks of the Week, new feature announcements, and more. ![spinner](https://www.paloaltonetworks.com/blog/wp-content/themes/panwblog2023/dist/images/ajax-loader.gif) Sign up Please enter a valid email. By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown) and acknowledge our [Privacy Statement](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown). Please look for a confirmation email from us. If you don't receive it in the next 10 minutes, please check your spam folder. This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply. {#footer} {#footer} ## Products and Services * [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security?ts=markdown) * [Secure AI by Design](https://www.paloaltonetworks.com/precision-ai-security/secure-ai-by-design?ts=markdown) * [Prisma AIRS](https://www.paloaltonetworks.com/prisma/prisma-ai-runtime-security?ts=markdown) * [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security?ts=markdown) * [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions?ts=markdown) * [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention?ts=markdown) * [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering?ts=markdown) * [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire?ts=markdown) * [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security?ts=markdown) * [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown) * [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security?ts=markdown) * [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security?ts=markdown) * [Industrial OT Security](https://www.paloaltonetworks.com/network-security/medical-device-security?ts=markdown) * [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown) * [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall?ts=markdown) * [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations?ts=markdown) * [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls?ts=markdown) * [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager?ts=markdown) * [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription?ts=markdown) * [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os?ts=markdown) * [Panorama](https://www.paloaltonetworks.com/network-security/panorama?ts=markdown) * [Secure Access Service Edge](https://www.paloaltonetworks.com/sase?ts=markdown) * [Prisma SASE](https://www.paloaltonetworks.com/sase?ts=markdown) * [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration?ts=markdown) * [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem?ts=markdown) * [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown) * [Prisma Access](https://www.paloaltonetworks.com/sase/access?ts=markdown) * [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser?ts=markdown) * [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan?ts=markdown) * [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation?ts=markdown) * [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown) * [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex?ts=markdown) * [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown) * [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown) * [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security?ts=markdown) * [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security?ts=markdown) * [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security?ts=markdown) * [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud?ts=markdown) * [AI-Driven SOC](https://www.paloaltonetworks.com/cortex?ts=markdown) * [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam?ts=markdown) * [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr?ts=markdown) * [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar?ts=markdown) * [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse?ts=markdown) * [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response?ts=markdown) * [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam?ts=markdown) * [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42?ts=markdown) * [Proactive Assessments](https://www.paloaltonetworks.com/unit42/assess?ts=markdown) * [Incident Response](https://www.paloaltonetworks.com/unit42/respond?ts=markdown) * [Transform Your Security Strategy](https://www.paloaltonetworks.com/unit42/transform?ts=markdown) * [Discover Threat Intelligence](https://www.paloaltonetworks.com/unit42/threat-intelligence-partners?ts=markdown) ## Company * [About Us](https://www.paloaltonetworks.com/about-us?ts=markdown) * [Careers](https://jobs.paloaltonetworks.com/en/) * [Contact Us](https://www.paloaltonetworks.com/company/contact-sales?ts=markdown) * [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility?ts=markdown) * [Customers](https://www.paloaltonetworks.com/customers?ts=markdown) * [Investor Relations](https://investors.paloaltonetworks.com/) * [Location](https://www.paloaltonetworks.com/about-us/locations?ts=markdown) * [Newsroom](https://www.paloaltonetworks.com/company/newsroom?ts=markdown) ## Popular Links * [Blog](https://www.paloaltonetworks.com/blog/?ts=markdown) * [Communities](https://www.paloaltonetworks.com/communities?ts=markdown) * [Content Library](https://www.paloaltonetworks.com/resources?ts=markdown) * [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia?ts=markdown) * [Event Center](https://events.paloaltonetworks.com/) * [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center) * [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z?ts=markdown) * [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/compliance?ts=markdown) * [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure?ts=markdown) * [Sitemap](https://www.paloaltonetworks.com/sitemap?ts=markdown) * [Tech Docs](https://docs.paloaltonetworks.com/) * [Unit 42](https://unit42.paloaltonetworks.com/) * [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd) ![PAN logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg) * [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown) * [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center?ts=markdown) * [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown) * [Documents](https://www.paloaltonetworks.com/legal?ts=markdown) Copyright © 2026 Palo Alto Networks. All Rights Reserved * [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks) * [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector?ts=markdown) * [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/) * [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks) * [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks) * EN Select your language