Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters.
Download CSV Show ATT&CK heatmapA user printed an unusual number of files Informational Identity Threat Module
A user printed an unusual number of files. This may be indicative of malicious activity and an attempt to exfiltrate data.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- 2 Hours
- Deduplication:
- 1 Day
ATT&CK tactics: Exfiltration (TA0010)ATT&CK techniques: Exfiltration Over Physical Medium (T1052)Required data: Windows Event Collector XDR Agent with eXtended Threat Hunting (XTH)Attacker's goals: In an attempt to exfiltrate data, a malicious insider might print an unusual number of files.Investigative actions: Check for any other suspicious activity related to the host and the user involved in the alert.