LogoLogo
search
⌘Ctrlk
  • book-blankDocumentation
  • file-linesRelease Notes
  • terminalAPI Reference
  • life-ringHelp Center
sparkle
AI Assistant
Working...Thinking...
sparkle
Good evening

I'm here to help you with the docs.

⌘Ctrli
AI Based on your contextquestion-circle
LogoLogo
  • 🏠Welcome
  • Deployment
    • Getting started
    • IDR for Azure AD & CDR for M365
    • CDR for AWS
    • CDR for Azure
    • NDR physical appliances
    • NDR virtual / cloud appliances
    • NDR Traffic engineering and validation
    • Match
    • Stream
    • Recall (QUX only)
    • Appliance operations
    • Deprecated / Retired
  • Configuration
    • Navigation updates (RUX)
    • ACCESS
    • COVERAGE
    • RESPONSE
    • SETUP
    • TUNING
    • QUX specific
  • Operations
    • Analyst Guidance
    • Updates
    • Dashboards and Reports
    • Detection Specific Guidance
      • Suspicious Remote Desktop
      • Hidden HTTPS Tunnel - detection showing proxy IP as target
      • Data Gathering - detected between Brain and Sensor
      • Suspect Protocol Activity detection descriptions
      • Turla and Snake malware
      • Suspicious Remote Execution
      • Intel AMT (Active Management Technology) detections
    • Licensing
    • Backup / Restore / DR
    • Investigate
    • General
  • Reference
    • Appliance EOS / EOL policy
    • Metadata attributes
    • Vectra's coverage of MITRE ATT&CK and D3FEND
    • Understanding Vectra host naming
    • How detection PCAPs are generated
    • RSPAN and ERSPAN support
    • AI-driven priortization FAQ
    • Bandwidth used between Sensor and Brain
    • AI and ML terminology
    • In-App support
    • Why is metadata sharing important
    • Product Security
    • Vectra UI supported browsers
block-quoteOn this pagechevron-down
  1. Operations

Detection Specific Guidance

Suspicious Remote Desktopchevron-rightHidden HTTPS Tunnel - detection showing proxy IP as targetchevron-rightData Gathering - detected between Brain and Sensorchevron-rightSuspect Protocol Activity detection descriptionschevron-rightTurla and Snake malwarechevron-rightSuspicious Remote Executionchevron-rightIntel AMT (Active Management Technology) detectionschevron-right
PreviousRecall host dashboardchevron-leftNextSuspicious Remote Desktopchevron-right

Last updated 1 month ago

Was this helpful?

LogoLogo
linkedinx-twitterfacebookyoutubeinstagramredditgithub

© 2026 Vectra AI, Inc. All rights reserved.

Was this helpful?