CDSS Threat Categories
Focus
Focus
Strata Cloud Manager

CDSS Threat Categories

Table of Contents

CDSS Threat Categories

Where Can I Use This?What Do I Need?
  • Prisma Access
    (with Strata Cloud Manager or Panorama configuration management)
  • NGFWs
    (with Strata Cloud Manager or Panorama configuration management)
You must have at least one of these licenses to use the Activity Insights:The other licenses needed to view the Activity Insights:Threats tab are:
  • Strata Logging Service
  • CDSS licenses
  • ADEM Observability will unlock additional Prisma Access features
Palo Alto Networks CDSS products classify security threats into logical categories to help you understand the threat landscape and create effective security policies. Threats fall into several major categories that are further categorized with increased specificity based on traffic patterns associated with the malicious activity of a subscription type. By organizing threats into these categories, Palo Alto Networks products enable you to detect, classify, and respond to threats more effectively, whether you're configuring policies, investigating incidents, or monitoring your security posture across your environment.
Threat Categories and corresponding threat subcategories are applicable only to Strata Cloud Manager based dashboards that are populated using data from Strata Logging service. For PAN-OS based threat log categories, refer to: Threat Signature Categories.
Threat Categories and Corresponding Sub-categories
Threat CategoryDescriptionSubscriptionSupported Sub-Categories
Reconnaissance & Pre-AttackActivities used to discover, test, and prepare for a full-scale attack, typically focused on gathering network intelligence.
Advanced Threat Prevention
  • Brute Force
  • Scanning Attack
Advanced URL Filtering
  • Scanning Attack
PhishingThreats focused on deceiving users, stealing credentials, or hijacking sessions via social engineering and malicious web infrastructure.
Advanced Threat Prevention
  • Phishing
  • Exploit-Kit
  • Insecure Credentials
  • Phishing-Kit
  • Trojan
Advanced URL Filtering
  • Phishing
Advanced DNS Security
  • Phishing
  • DNS Phishing
Advanced WildFire
  • Phishing
  • Exploit
  • Evasive
  • Spyware
  • Trojan
Malware Executables, droppers, and advanced payloads designed for system compromise, persistence, and evasion techniques.
Advanced Threat Prevention
  • Spyware
  • Net Worm
  • Auto-Gen
  • Downloader
  • TLS Fingerprinting
  • Virus
Advanced URL Filtering
  • Malware
  • Compromised Website
Advanced DNS Security
  • Malware
  • Spyware
Advanced WildFire
  • Worm
  • Virus
Exploitation and Code-executionAttacks targeting software vulnerabilities and insecure coding practices within web applications and network services (Initial Access/Execution).
Advanced Threat Prevention
  • Code Execution
  • Overflow
  • SQL Injection
  • Command Injection
  • Command Execution
  • Code Obfuscation
  • Inline Command Injection
  • Inline SQL Injection
Post-Exploitation & Lateral Movement
Adversary tools and frameworks used after initial access for command execution, data gathering, and expanding control (Persistence/Lateral Movement).
Advanced Threat Prevention
  • Autogen
  • Cryptominer
  • Fraud
  • Hacktool
  • Keylogger
  • Post Exploitation
Command & Control (C2) & ExfiltrationTechniques and infrastructure used for maintaining communication with compromised systems and covertly transferring data out of the network.
Advanced Threat Prevention
  • Adware
  • Backdoor
  • Botnet
  • Browser Hijack
  • Data Theft
  • Webshell
  • Evasive C2 over HTTP
  • Evasive C2 over HTTP/2
  • Evasive C2 over SSL/TLS
  • Evasive C2 over Unknown-TCP
  • Evasive C2 over Unknown-UDP
  • Evasive Cobalt Strike C2 Traffic
  • Evasive Cobalt Strike C2 Cross Section Traffic
  • Evasive Empire C2 Traffic
  • HTTP Data Exfiltration via FQDN Using Suspicious Domain
  • HTTP2 Data Exfiltration via FQDN Using Suspicious Domain
  • Evasive Sliver C2 Traffic
  • Info Leak
Advanced URL Filtering
  • Command and Control URLs
Advanced DNS Security
  • Command and Control Domains
Disruption & ExtortionThreats explicitly aimed at system disruption, denial of service, resource abuse, and achieving financial or operational impact.
Advanced Threat Prevention
  • Denial of Service
Advanced URL Filtering
  • Grayware
  • Ransomware
  • Copyright Infringement
  • Extremism
  • Unknown
  • Cryptocurrency
  • Peer-to-Peer
  • Questionable
Advanced WildFire
  • Grayware
Advanced DNS Security
  • Grayware
  • Copyright Infringement
  • Extremism
  • Unknown
  • Cryptocurrency
  • Peer-to-Peer
  • Questionable
Network Protocol AbuseAttacks and anomalies that exploit the Domain Name System (DNS) infrastructure or violate established network protocol rules for attack or evasion.
Advanced Threat Prevention
  • Protocol Anomaly
  • Cross-Site Scripting
Advanced DNS Security
  • Compromised DNS Registrar
  • DNS Misconfiguration
  • DNS Hijacking
Adversary infrastructureInfrastructure-based threats designed to host attacks, bypass security controls, and conceal true operational sources.
Advanced URL Filtering
  • Parked Domains
  • Dynamic DNS
  • Proxy Domains
  • Newly Registered Domains
  • Hacking URLs and Domains
Advanced DNS Security
  • Ad Tracking
  • New Domains
  • Parked Domains
  • Dynamic DNS
  • Proxy Domains
  • Hacking URLs and Domains