Analytics
Informational
✕
A user printed an unusual number of files
A user printed an unusual number of files. This may be indicative of malicious activity and an attempt to exfiltrate data.
- Module:
- Identity Threat Detection (ITDR)
- Licensed by:
- Identity Threat Detection (ITDR)
- Data source:
- Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Exfiltration (TA0010)
ATT&CK techniques: Exfiltration Over Physical Medium (T1052)
Attacker's goals:
In an attempt to exfiltrate data, a malicious insider might print an unusual number of files.
Investigative actions:
Check for any other suspicious activity related to the host and the user involved in the alert.
- Test period:
- 2 Hours
- Deduplication:
- 1 Day