Analytics
Informational
✕
Massive upload to a rare storage or mail domain
A large amount of data was transferred to an external site that is used for mail or storage. This behavior may indicate data exfiltration.
- Module:
- Identity Threat Detection (ITDR), SaaS Threat Detection
- Licensed by:
- Identity Threat Detection (ITDR)
- Data source:
- Palo Alto Networks Firewall EAL Logs, Palo Alto Networks Firewall threat Logs, XDR Agent
ATT&CK tactics: Exfiltration (TA0010)
ATT&CK techniques: Exfiltration Over Web Service (T1567) Exfiltration Over Web Service: Exfiltration to Cloud Storage (T1567.002)
Detector tags: Data Detection & Response
Attacker's goals:
A user uploaded an abnormal amount of data to a file sharing service. This activity might indicate an attempt to exfiltrate files and data from the organization.
Investigative actions:
Check for any other suspicious activity related to the host and the user involved in the alert. Identify the user uploading the data to determine if the transfer is sanctioned.
- Test period:
- 1 Hour
- Deduplication:
- 1 Day
1 variation:
- A user uploaded over 500 MB to a rare storage or mail domain Low (parent: Informational)