Outlook files accessed by an unsigned process
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
1 Hour
Deduplication Period
1 Day
Required Data
XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK Tactic
Collection (TA0009)
ATT&CK Technique
Data Staged: Local Data Staging (T1074.001), Email Collection: Local Email Collection (T1114.001)
Severity
Low
Description
An attacker may use an uncommon and unsigned process to access Outlook data files.
Attacker's Goals
Gain access to the data in the compromised mailbox.
Investigative actions
Examine the process command and file activity to identify the mailbox.
Check if the process performed any other suspicious file activity.
Check if the process generated network connections.
PreviousOutbound email to an address hosted by a public email service provider
NextOwner added to Azure application
Was this helpful?
