Analytics BIOC Informational

WebDAV drive mounted from net.exe over HTTPS

Attackers may mount a WebDAV drive over HTTPS to upload files to and download files from a compromised machine.

Module:
Platform Analytics
Data source:
XDR Agent
ATT&CK tactics: Exfiltration (TA0010)
ATT&CK techniques: Exfiltration Over Alternative Protocol (T1048)
Attacker's goals:

Attackers might use WebDAV as a C&C or exfiltration channel to evade detection and firewall rules.

Investigative actions:

Check whether the initiator process is benign or normal for the host and/or user performing it. Check whether additional malicious commands were executed from the same process.

Test period:
N/A (single event)
Deduplication:
1 Day