Unusual process accessed a crypto wallet's files
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent with eXtended Threat Hunting (XTH)
Detector Tags
Sensitive Information Stealing Analytics
ATT&CK Tactic
Collection (TA0009)
ATT&CK Technique
Data from Local System (T1005)
Severity
Low
Description
An unusual process has accessed files belonging to a cryptocurrency wallet.
Attacker's Goals
Obtain access to cryptocurrency stored in the wallet.
Investigative actions
Determine whether it is legitimate for the process to access such files.
Analyze the process/application that accessed the file.
Check for any other suspicious actions that were performed by the process.
Audit the usage of the cryptocurrency stored in the wallet.
PreviousUnusual process access to ld.so.preload file
NextUnusual process accessed a macOS notes DB file
Was this helpful?
