Focus
Focus
Table of Contents

Credential Theft

Collects information on the firewall's credential theft policy usage. Examines URL logs for traffic where credentials are presented, and collects information about the username, destination zone, the action the firewall took in response to the traffic, the application in use, and the URL used for the traffic. Also identifies the security and profiles used by the firewall to determine the action that it took for this traffic.

Metric Details

Category
Threat Prevention
This metric can be used for threat research.
Can identify a user.
Once a week
Introduced
Content version 8284
Telemetry Tier
Full
Equivalent CLI Command
pan_logquery -b -t url -n 5000 -e last-7-days -q '( flags has credential-detected )'