A user took numerous screenshots
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
1 Hour
Deduplication Period
1 Day
Required Data
XDR Agent with eXtended Threat Hunting (XTH)
Detection Modules
Identity Threat Module
ATT&CK Tactic
Collection (TA0009)
ATT&CK Technique
Screen Capture (T1113), Data Staged: Local Data Staging (T1074.001)
Severity
Informational
Description
A user took numerous screenshots. A valuable organization's information may have been collected in this way.
Attacker's Goals
Collect data and stage it on an endpoint in the organization.
Investigative actions
Check whether this activity fits the user profile.
Check for any other suspicious activity related to the host and the user involved in the alert.
Check if there was a suspicious file upload following the massive screenshot activity.
Check whether other users in the organization used the same process for file activity.
Was this helpful?
