> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/abnormal-file-activity-in-sccmcontentlib-shared-folder-by-user.md).

# Abnormal File Activity in SCCMContentLib Shared Folder by user

### Synopsis

| Field                | Value                                                                      |
| -------------------- | -------------------------------------------------------------------------- |
| Activation Period    | 14 Days                                                                    |
| Training Period      | 30 Days                                                                    |
| Test Period          | 30 Minutes                                                                 |
| Deduplication Period | 1 Day                                                                      |
| Required Data        | XDR Agent with eXtended Threat Hunting (XTH)                               |
| Detection Modules    | Identity Analytics                                                         |
| Detector Tags        | Microsoft SCCM Analytics                                                   |
| ATT\&CK Tactic       | Credential Access (TA0006), Privilege Escalation (TA0004)                  |
| ATT\&CK Technique    | Valid Accounts: Domain Accounts (T1078.002), Unsecured Credentials (T1552) |
| Severity             | Informational                                                              |

### Description

A user generated suspicious file activity within the SCCMContentLib shared folder, which is considered a high-value target for attackers.

### Attacker's Goals

Attackers aim to exploit misconfigurations in Microsoft Configuration Manager to access sensitive data, such as credentials and certificates, stored within the SCCMContentLib. This access can facilitate lateral movement and further compromise within the network.

### Investigative actions

* Verify the activity with the performing user.
* Check if SCCM admin credentials were accessed or exfiltrated.
* Review SCCM logs to identify unauthorized queries or modifications.
* Investigate recent access to the extracted files and their contents.
* Check other security logs (e.g., Windows Event Logs, SIEM alerts) for suspicious behavior.
* Identify the originating system and assess if it has been compromised.
* Monitor for any further lateral movement or privilege escalation attempts.

### Variations

<details>

<summary>Suspicious File Activity in SCCMContentLib Shared Folder by user</summary>

**Synopsis**

| Field             | Value                                                                      |
| ----------------- | -------------------------------------------------------------------------- |
| ATT\&CK Tactic    | Credential Access (TA0006), Privilege Escalation (TA0004)                  |
| ATT\&CK Technique | Valid Accounts: Domain Accounts (T1078.002), Unsecured Credentials (T1552) |
| Severity          | Low                                                                        |

**Description**

A user generated suspicious file activity within the SCCMContentLib shared folder, which is considered a high-value target for attackers.

**Attacker's Goals**

Attackers aim to exploit misconfigurations in Microsoft Configuration Manager to access sensitive data, such as credentials and certificates, stored within the SCCMContentLib. This access can facilitate lateral movement and further compromise within the network.

**Investigative actions**

* Verify the activity with the performing user.
* Check if SCCM admin credentials were accessed or exfiltrated.
* Review SCCM logs to identify unauthorized queries or modifications.
* Investigate recent access to the extracted files and their contents.
* Check other security logs (e.g., Windows Event Logs, SIEM alerts) for suspicious behavior.
* Identify the originating system and assess if it has been compromised.
* Monitor for any further lateral movement or privilege escalation attempts.

</details>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/abnormal-file-activity-in-sccmcontentlib-shared-folder-by-user.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
