Analytics BIOC
Low
✕
Unusual process accessed FTP Client credentials
An unusual process has accessed a third-party FTP client's credential file.
- Module:
- Platform Analytics
- Data source:
- XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Credential Access (TA0006)
ATT&CK techniques: Unsecured Credentials: Credentials In Files (T1552.001)
Detector tags: Credentials Grabbing Analytics
Attacker's goals:
Obtain access to passwords stored in the FTP client.
Investigative actions:
Determine whether it is legitimate for the process to access FTP passwords directly. Analyze the process/application that accessed the credentials. Check for any other suspicious actions that were performed by the process. Look for unusual access to resources using credentials cached in the FTP client.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day