Analytics
Informational
✕
Massive file activity abnormal to process
A user generated massive file activity by size or distinct file count.
- Module:
- Identity Threat Detection (ITDR)
- Licensed by:
- Identity Threat Detection (ITDR)
- Data source:
- XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Collection (TA0009)
ATT&CK techniques: Automated Collection (T1119) Data Staged: Local Data Staging (T1074.001)
Detector tags: Data Detection & Response
Attacker's goals:
Collect data and stage it on an endpoint in the organization.
Investigative actions:
Check whether the process that created the massive file activity creates network connections as well. Check which files the process performed the activity on. Check whether other users in the organization used the same process for file activity.
- Test period:
- 1 Hour
- Deduplication:
- 1 Day
1 variation:
- Massive file activity over 500 MB abnormal to process Low (parent: Informational)