Massive file activity abnormal to process
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
1 Hour
Deduplication Period
1 Day
Required Data
XDR Agent with eXtended Threat Hunting (XTH)
Detection Modules
Identity Threat Module
Detector Tags
Data Detection & Response
ATT&CK Tactic
Collection (TA0009)
ATT&CK Technique
Automated Collection (T1119), Data Staged: Local Data Staging (T1074.001)
Severity
Informational
Description
A user generated massive file activity by size or distinct file count.
Attacker's Goals
Collect data and stage it on an endpoint in the organization.
Investigative actions
Check whether the process that created the massive file activity creates network connections as well.
Check which files the process performed the activity on.
Check whether other users in the organization used the same process for file activity.
Variations
Was this helpful?
