An uncommon executable was remotely written over SMB to an uncommon destination
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK Tactic
Lateral Movement (TA0008)
ATT&CK Technique
Remote Services: SMB/Windows Admin Shares (T1021.002)
Severity
Low
Description
An uncommon executable was remotely written over SMB to a destination, which was not involved in significant similar activity during last month.
Attacker's Goals
Transfer tools as part of lateral movement activity across the network.
Investigative actions
Verify if the shared file is malicious.
Investigate if the file was executed on the host.
Check the remote SMB client for other suspicious activities.
Variations
PreviousAn S3 replication policy to an unknown bucket was created
NextAn uncommon file added to startup-related Registry keys
Was this helpful?
