Uncommon attempt at discovering a sensitive file
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent with eXtended Threat Hunting (XTH)
Detector Tags
EDR Discovery Analytics
ATT&CK Tactic
Discovery (TA0007)
ATT&CK Technique
File and Directory Discovery (T1083), Process Discovery (T1057), System Service Discovery (T1007), System Network Configuration Discovery (T1016), System Owner/User Discovery (T1033), System Network Connections Discovery (T1049), System Information Discovery (T1082)
Severity
Informational
Description
A process made an uncommon attempt to access a file that may contain sensitive information.
Attacker's Goals
Attackers may attempt to access sensitive files to steal credentials, perform reconnaissance on system configurations and users, and find pathways for lateral movement.
Investigative actions
Review the event's context - examine the process, its command line, and its origin to gain a comprehensive understanding of the anomalous access.* Assess the behavior's legitimacy: Given that this is an uncommon event, determine if this file access is an expected and authorized behavior for the actor process.
Variations
Was this helpful?
