Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source
  • A user accessed an abnormal number of files on a remote shared folder Informational Identity Threat Module

    A user remotely accessed an abnormal number of files on a remote shared folder. This might indicate an attempt to collect data before exfiltration.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    1 Hour
    Deduplication:
    1 Day
    ATT&CK tactics: Discovery (TA0007)
    ATT&CK techniques: File and Directory Discovery (T1083)
    Required data: XDR Agent with eXtended Threat Hunting (XTH)
    Detector tags: Data Detection & Response
    Attacker's goals: Collect valuable data about the organization for exfiltration purposes.
    Investigative actions: Check for other suspicious activity made by the user at the time of the event. Go over the list of files and check if such user should have access to those files.