Analytics BIOC
Low
✕
Unusual process accessed a crypto wallet's files
An unusual process has accessed files belonging to a cryptocurrency wallet.
- Module:
- Platform Analytics
- Data source:
- XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Collection (TA0009)
ATT&CK techniques: Data from Local System (T1005)
Detector tags: Sensitive Information Stealing Analytics
Attacker's goals:
Obtain access to cryptocurrency stored in the wallet.
Investigative actions:
Determine whether it is legitimate for the process to access such files. Analyze the process/application that accessed the file. Check for any other suspicious actions that were performed by the process. Audit the usage of the cryptocurrency stored in the wallet.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day