Possible data exfiltration over a USB storage device
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
1 Hour
Deduplication Period
1 Day
Required Data
XDR Agent with eXtended Threat Hunting (XTH)
Detection Modules
Identity Threat Module
ATT&CK Tactic
Collection (TA0009), Exfiltration (TA0010)
ATT&CK Technique
Exfiltration Over Physical Medium: Exfiltration over USB (T1052.001), Data Staged: Local Data Staging (T1074.001)
Severity
Informational
Description
A process generated massive file creation, renaming and write activity to a USB storage device.
Attacker's Goals
Collect data and stage it on an endpoint in the organization.
Investigative actions
Check whether the process that created the massive file activity creates network connections as well.
Check whether the USB storage device is new to the organization.
Check whether other users in the organization used the same process for massive file activity.
Was this helpful?
