For the complete documentation index, see llms.txt. This page is also available as Markdown.

Massive file activity abnormal to process

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

1 Hour

Deduplication Period

1 Day

Required Data

XDR Agent with eXtended Threat Hunting (XTH)

Detection Modules

Identity Threat Module

Detector Tags

Data Detection & Response

ATT&CK Tactic

Collection (TA0009)

ATT&CK Technique

Automated Collection (T1119), Data Staged: Local Data Staging (T1074.001)

Severity

Informational

Description

A user generated massive file activity by size or distinct file count.

Attacker's Goals

Collect data and stage it on an endpoint in the organization.

Investigative actions

  • Check whether the process that created the massive file activity creates network connections as well.

  • Check which files the process performed the activity on.

  • Check whether other users in the organization used the same process for file activity.

Variations

Massive file activity over 500 MB abnormal to process

Synopsis

Field
Value

ATT&CK Tactic

Collection (TA0009)

ATT&CK Technique

Automated Collection (T1119), Data Staged: Local Data Staging (T1074.001)

Severity

Low

Description

A user generated massive file activity by size or distinct file count.

Attacker's Goals

Collect data and stage it on an endpoint in the organization.

Investigative actions

  • Check whether the process that created the massive file activity creates network connections as well.

  • Check which files the process performed the activity on.

  • Check whether other users in the organization used the same process for file activity.

Was this helpful?