For the complete documentation index, see llms.txt. This page is also available as Markdown.

Unusual process accessed FTP Client credentials

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

XDR Agent with eXtended Threat Hunting (XTH)

Detector Tags

Credentials Grabbing Analytics

ATT&CK Tactic

Credential Access (TA0006)

ATT&CK Technique

Unsecured Credentials: Credentials In Files (T1552.001)

Severity

Low

Description

An unusual process has accessed a third-party FTP client's credential file.

Attacker's Goals

Obtain access to passwords stored in the FTP client.

Investigative actions

  • Determine whether it is legitimate for the process to access FTP passwords directly.

  • Analyze the process/application that accessed the credentials.

  • Check for any other suspicious actions that were performed by the process.

  • Look for unusual access to resources using credentials cached in the FTP client.

Was this helpful?