Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. technique: T1114 ✕
Download CSV Show ATT&CK heatmapOutlook files accessed by an unsigned process Low
An attacker may use an uncommon and unsigned process to access Outlook data files.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- 1 Hour
- Deduplication:
- 1 Day
ATT&CK tactics: Collection (TA0009)ATT&CK techniques: Data Staged: Local Data Staging (T1074.001) Email Collection: Local Email Collection (T1114.001)Required data: XDR Agent with eXtended Threat Hunting (XTH)Attacker's goals: Gain access to the data in the compromised mailbox.Investigative actions: Examine the process command and file activity to identify the mailbox. Check if the process performed any other suspicious file activity. Check if the process generated network connections.