Analytics Informational

A user printed an unusual number of files

A user printed an unusual number of files. This may be indicative of malicious activity and an attempt to exfiltrate data.

Module:
Identity Threat Detection (ITDR)
Licensed by:
Identity Threat Detection (ITDR)
Data source:
Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Exfiltration (TA0010)
ATT&CK techniques: Exfiltration Over Physical Medium (T1052)
Attacker's goals:

In an attempt to exfiltrate data, a malicious insider might print an unusual number of files.

Investigative actions:

Check for any other suspicious activity related to the host and the user involved in the alert.

Test period:
2 Hours
Deduplication:
1 Day