Massive upload to a rare storage or mail domain
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
1 Hour
Deduplication Period
1 Day
Required Data
Requires all of the following: Palo Alto Networks Firewall EAL Logs OR Palo Alto Networks Firewall threat Logs XDR Agent
Detection Modules
Identity Threat Module, SaaS Threat Detection
Detector Tags
Data Detection & Response
ATT&CK Tactic
Exfiltration (TA0010)
ATT&CK Technique
Exfiltration Over Web Service (T1567), Exfiltration Over Web Service: Exfiltration to Cloud Storage (T1567.002)
Severity
Informational
Description
A large amount of data was transferred to an external site that is used for mail or storage. This behavior may indicate data exfiltration.
Attacker's Goals
A user uploaded an abnormal amount of data to a file sharing service. This activity might indicate an attempt to exfiltrate files and data from the organization.
Investigative actions
Check for any other suspicious activity related to the host and the user involved in the alert.
Identify the user uploading the data to determine if the transfer is sanctioned.
Variations
Was this helpful?
