WebDAV drive mounted from net.exe over HTTPS
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent
ATT&CK Tactic
Exfiltration (TA0010)
ATT&CK Technique
Exfiltration Over Alternative Protocol (T1048)
Severity
Informational
Description
Attackers may mount a WebDAV drive over HTTPS to upload files to and download files from a compromised machine.
Attacker's Goals
Attackers might use WebDAV as a C&C or exfiltration channel to evade detection and firewall rules.
Investigative actions
Check whether the initiator process is benign or normal for the host and/or user performing it.
Check whether additional malicious commands were executed from the same process.
PreviousWeb server CGO executed an uncommon process
NextWell-known brand in sender headers with header inconsistencies
Was this helpful?
