For the complete documentation index, see llms.txt. This page is also available as Markdown.

Possible internal data exfiltration over a USB storage device

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

1 Hour

Deduplication Period

1 Day

Required Data

XDR Agent with eXtended Threat Hunting (XTH)

Detection Modules

Identity Threat Module

ATT&CK Tactic

Collection (TA0009), Exfiltration (TA0010)

ATT&CK Technique

Exfiltration Over Physical Medium: Exfiltration over USB (T1052.001), Data Staged: Local Data Staging (T1074.001)

Severity

Informational

Description

A user generated abnormal massive file activity to a connected USB storage device.

Attacker's Goals

Collect data and stage it on an endpoint in the organization.

Investigative actions

  • Check whether the process that created the massive file activity creates network connections as well.

  • Check whether the USB storage device is new to the organization.

  • Check whether other users in the organization used the same process for massive file activity.

Variations

Possible internal data exfiltration of over 500 MB via USB storage device

Synopsis

Field
Value

ATT&CK Tactic

Collection (TA0009), Exfiltration (TA0010)

ATT&CK Technique

Exfiltration Over Physical Medium: Exfiltration over USB (T1052.001), Data Staged: Local Data Staging (T1074.001)

Severity

Low

Description

A user generated abnormal massive file activity to a connected USB storage device.

Attacker's Goals

Collect data and stage it on an endpoint in the organization.

Investigative actions

  • Check whether the process that created the massive file activity creates network connections as well.

  • Check whether the USB storage device is new to the organization.

  • Check whether other users in the organization used the same process for massive file activity.

Was this helpful?