Analytics BIOC Low

Unusual process accessed FTP Client credentials

An unusual process has accessed a third-party FTP client's credential file.

Module:
Platform Analytics
Data source:
XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Credential Access (TA0006)
ATT&CK techniques: Unsecured Credentials: Credentials In Files (T1552.001)
Detector tags: Credentials Grabbing Analytics
Attacker's goals:

Obtain access to passwords stored in the FTP client.

Investigative actions:

Determine whether it is legitimate for the process to access FTP passwords directly. Analyze the process/application that accessed the credentials. Check for any other suspicious actions that were performed by the process. Look for unusual access to resources using credentials cached in the FTP client.

Test period:
N/A (single event)
Deduplication:
1 Day