Analytics Informational

SCCM log files enumeration

Multiple local SCCM logs were accessed within a short period of time.

Module:
Identity Analytics
Data source:
XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Discovery (TA0007)
ATT&CK techniques: Log Enumeration (T1654)
Detector tags: Microsoft SCCM Analytics
Attacker's goals:

Enumerate data about the SCCM configuration, infrastructure and deployments.

Investigative actions:

Check suspicious network connections from the process or host. Check if the user account that initiated the enumeration is supposed to access these files.

Test period:
1 Hour
Deduplication:
1 Day
1 variation:
  • Suspicious SCCM log files enumeration Low (parent: Informational)