Analytics Informational

Massive upload to a rare storage or mail domain

A large amount of data was transferred to an external site that is used for mail or storage. This behavior may indicate data exfiltration.

Module:
Identity Threat Detection (ITDR), SaaS Threat Detection
Licensed by:
Identity Threat Detection (ITDR)
Data source:
Palo Alto Networks Firewall EAL Logs, Palo Alto Networks Firewall threat Logs, XDR Agent
ATT&CK tactics: Exfiltration (TA0010)
ATT&CK techniques: Exfiltration Over Web Service (T1567) Exfiltration Over Web Service: Exfiltration to Cloud Storage (T1567.002)
Detector tags: Data Detection & Response
Attacker's goals:

A user uploaded an abnormal amount of data to a file sharing service. This activity might indicate an attempt to exfiltrate files and data from the organization.

Investigative actions:

Check for any other suspicious activity related to the host and the user involved in the alert. Identify the user uploading the data to determine if the transfer is sanctioned.

Test period:
1 Hour
Deduplication:
1 Day
1 variation:
  • A user uploaded over 500 MB to a rare storage or mail domain Low (parent: Informational)