Uncommon file access over WebDAV
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK Tactic
Command and Control (TA0011)
ATT&CK Technique
Application Layer Protocol: Web Protocols (T1071.001)
Severity
Low
Description
Uncommon file access over WebDAV.
Attacker's Goals
Threat actors may use the WebDAV to blend in existing network traffic.
Investigative actions
Investigate the process {actor_process_image_name} which tried to access the remote file.
Investigate the remote host {webdav_dst_from_file_event}.
Variations
PreviousUncommon execution of ODBCConf
NextUncommon GetClipboardData API function invocation of a possible information stealer
Was this helpful?
