A user printed an unusual number of files
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
2 Hours
Deduplication Period
1 Day
Required Data
Requires one of the following data sources: Windows Event Collector OR XDR Agent with eXtended Threat Hunting (XTH)
Detection Modules
Identity Threat Module
ATT&CK Tactic
Exfiltration (TA0010)
ATT&CK Technique
Exfiltration Over Physical Medium (T1052)
Severity
Informational
Description
A user printed an unusual number of files. This may be indicative of malicious activity and an attempt to exfiltrate data.
Attacker's Goals
In an attempt to exfiltrate data, a malicious insider might print an unusual number of files.
Investigative actions
Check for any other suspicious activity related to the host and the user involved in the alert.
PreviousA user performed suspiciously massive file activity
NextA user queried AD CS objects via LDAP
Was this helpful?
