Analytics
Low
✕
Outlook files accessed by an unsigned process
An attacker may use an uncommon and unsigned process to access Outlook data files.
- Module:
- Platform Analytics
- Data source:
- XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Collection (TA0009)
ATT&CK techniques: Data Staged: Local Data Staging (T1074.001) Email Collection: Local Email Collection (T1114.001)
Attacker's goals:
Gain access to the data in the compromised mailbox.
Investigative actions:
Examine the process command and file activity to identify the mailbox. Check if the process performed any other suspicious file activity. Check if the process generated network connections.
- Test period:
- 1 Hour
- Deduplication:
- 1 Day