Analytics BIOC
Low
✕
Unusual process accessed a messaging app's files
An unusual process has accessed files belonging to a messaging app.
- Module:
- Platform Analytics
- Data source:
- XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Collection (TA0009) Reconnaissance (TA0043)
ATT&CK techniques: Data from Local System (T1005) Gather Victim Host Information (T1592)
Detector tags: Sensitive Information Stealing Analytics
Attacker's goals:
Obtain access to the user's message history and steal their contents.
Investigative actions:
Determine whether it is legitimate for the process to access such files. Analyze the process/application that accessed the file. Check for any other suspicious actions that were performed by the process. Look for unusual access of resources using credentials that may have been associated with the above messaging app.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day