Analytics BIOC High

Suspicious usage of File Server Remote VSS Protocol (FSRVP)

A suspicious usage of File Server Remote VSS Protocol (FSRVP) was done.

Module:
Platform Analytics
Data source:
XDR Agent
ATT&CK tactics: Lateral Movement (TA0008)
ATT&CK techniques: Use Alternate Authentication Material: Pass the Hash (T1550.002)
Attacker's goals:

An attacker is attempting to steal credentials and move laterally within a network.

Investigative actions:

Check for suspicious processes on the source host. Check if the source host is a vulnerability scanner. Look for additional suspicious activities by users.

Test period:
N/A (single event)
Deduplication:
1 Day