Analytics
Informational
✕
A user accessed an abnormal number of remote shared folders
A user accessed an abnormal number of remote shared folders. This might indicate an attempt to collect data before exfiltration.
- Module:
- Identity Threat Detection (ITDR)
- Licensed by:
- Identity Threat Detection (ITDR)
- Data source:
- XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Collection (TA0009)
ATT&CK techniques: Data from Network Shared Drive (T1039)
Detector tags: Data Detection & Response
Attacker's goals:
Collect valuable data about the organization for exfiltration purposes.
Investigative actions:
Check for other suspicious activity made by the user at the time of the event. Inspect the shared folder and verify if the user should have accessed to that folder. Go over the list of files and check if such user should have access to those files.
- Test period:
- 1 Hour
- Deduplication:
- 1 Day
1 variation:
- A user accessed an abnormal number of remote shared folders for the first time Low (parent: Informational)