Analytics
Informational
✕
Possible data exfiltration over a USB storage device
A process generated massive file creation, renaming and write activity to a USB storage device.
- Module:
- Identity Threat Detection (ITDR)
- Licensed by:
- Identity Threat Detection (ITDR)
- Data source:
- XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Collection (TA0009) Exfiltration (TA0010)
ATT&CK techniques: Exfiltration Over Physical Medium: Exfiltration over USB (T1052.001) Data Staged: Local Data Staging (T1074.001)
Attacker's goals:
Collect data and stage it on an endpoint in the organization.
Investigative actions:
Check whether the process that created the massive file activity creates network connections as well. Check whether the USB storage device is new to the organization. Check whether other users in the organization used the same process for massive file activity.
- Test period:
- 1 Hour
- Deduplication:
- 1 Day