Analytics BIOC Low

Unusual process accessed a crypto wallet's files

An unusual process has accessed files belonging to a cryptocurrency wallet.

Module:
Platform Analytics
Data source:
XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Collection (TA0009)
ATT&CK techniques: Data from Local System (T1005)
Detector tags: Sensitive Information Stealing Analytics
Attacker's goals:

Obtain access to cryptocurrency stored in the wallet.

Investigative actions:

Determine whether it is legitimate for the process to access such files. Analyze the process/application that accessed the file. Check for any other suspicious actions that were performed by the process. Audit the usage of the cryptocurrency stored in the wallet.

Test period:
N/A (single event)
Deduplication:
1 Day