What are the Unique Threat IDs for Advanced Threat Prevention (ATP)?
1916
Created On 12/05/24 17:04 PM - Last Modified 10/28/25 19:55 PM
Question
What are the Unique Threat IDs for Advanced Threat Prevention (ATP)?
Environment
- Palo Alto Firewalls
- PANOS 10.2 and above
Answer
| Profile Type | Threat Name | Threat ID | Severity | Min PANOS Version |
| Vulnerability | Inline Cloud Analyzed SQL Injection Traffic Detection | 99950 | High | 11.0.2 |
| Vulnerability | Inline Cloud Analyzed CMD Injection Traffic Detection | 99951 | High | 11.0.2 |
| Spyware | Evasive HTTP C2 Traffic Detection | 89950 | High | 10.2 |
| Spyware | Inline Cloud Analyzed HTTP2 Command and Control Traffic Detection | 89951 | High | 10.2 |
| Spyware | Evasive Cobalt Strike C2 Traffic Detection | 89955 | High | 11.0.2 |
| Spyware | Evasive Cobalt Strike C2 Traffic Detection | 89956 | High | 10.2 |
| Spyware | Evasive Cobalt Strike C2 Cross Session Traffic Detection | 89957 | High | 11.0.2 |
| Spyware | Evasive Empire C2 Traffic Detection | 89958 | High | 11.0.2 |
| Spyware | Evasive Sliver C2 Traffic Detection | 89961 | High | 11.2.7 |
| Spyware | Inline Cloud Analyzed SSL Command and Control Traffic Detection | 89952 | High | 10.2 |
| Spyware | Inline Cloud Analyzed Unknown-TCP Command and Control Traffic Detection | 89953 | High | 10.2 |
| Spyware | Inline Cloud Analyzed Unknown-UDP Command and Control Traffic Detection | 89954 | High | 10.2 |