For the complete documentation index, see llms.txt. This page is also available as Markdown.

WebDAV drive mounted from net.exe over HTTPS

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

XDR Agent

ATT&CK Tactic

Exfiltration (TA0010)

ATT&CK Technique

Exfiltration Over Alternative Protocol (T1048)

Severity

Informational

Description

Attackers may mount a WebDAV drive over HTTPS to upload files to and download files from a compromised machine.

Attacker's Goals

Attackers might use WebDAV as a C&C or exfiltration channel to evade detection and firewall rules.

Investigative actions

  • Check whether the initiator process is benign or normal for the host and/or user performing it.

  • Check whether additional malicious commands were executed from the same process.

Was this helpful?