File transfer from unusual IP using known tools
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent
Detector Tags
Kubernetes - AGENT, Containers
ATT&CK Tactic
Command and Control (TA0011)
ATT&CK Technique
Ingress Tool Transfer (T1105)
Severity
Informational
Description
An adversary might use known tools to transfer tools/payloads into the compromised machine.
Attacker's Goals
Expand attack vectors and compromise the rest of the network.
Investigative actions
Check if the action was done using an automation service.
Check if there are any other suspicious activities originated from the same machine/executing user.
Variations
Was this helpful?
