Analytics BIOC Informational

File transfer from unusual IP using known tools

An adversary might use known tools to transfer tools/payloads into the compromised machine.

Module:
Platform Analytics
Data source:
XDR Agent
ATT&CK tactics: Command and Control (TA0011)
ATT&CK techniques: Ingress Tool Transfer (T1105)
Detector tags: Kubernetes - AGENT Containers
Attacker's goals:

Expand attack vectors and compromise the rest of the network.

Investigative actions:

Check if the action was done using an automation service. Check if there are any other suspicious activities originated from the same machine/executing user.

Test period:
N/A (single event)
Deduplication:
1 Day
1 variation:
  • File transfer from unusual IP using known tools in a Kubernetes pod Low (parent: Informational)