Analytics BIOC
Low
✕
Uncommon file access over WebDAV
Uncommon file access over WebDAV.
- Module:
- Platform Analytics
- Data source:
- XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Command and Control (TA0011)
ATT&CK techniques: Application Layer Protocol: Web Protocols (T1071.001)
Attacker's goals:
Threat actors may use the WebDAV to blend in existing network traffic.
Investigative actions:
Investigate the process {actor_process_image_name} which tried to access the remote file. Investigate the remote host {webdav_dst_from_file_event}.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
1 variation:
- High-risk file read over WebDAV by a LOLBIN process High (parent: Low)