Analytics
Informational
✕
SCCM log files enumeration
Multiple local SCCM logs were accessed within a short period of time.
- Module:
- Identity Analytics
- Data source:
- XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Discovery (TA0007)
ATT&CK techniques: Log Enumeration (T1654)
Detector tags: Microsoft SCCM Analytics
Attacker's goals:
Enumerate data about the SCCM configuration, infrastructure and deployments.
Investigative actions:
Check suspicious network connections from the process or host. Check if the user account that initiated the enumeration is supposed to access these files.
- Test period:
- 1 Hour
- Deduplication:
- 1 Day
1 variation:
- Suspicious SCCM log files enumeration Low (parent: Informational)