A user printed an unusual number of files

Cortex XDR Analytics Alert Reference by Alert name

Product
Cortex XDR
Last date published
2024-09-24
Category
Analytics Alert Reference
Order
Alert name

Synopsis

Activation Period

14 Days

Training Period

30 Days

Test Period

2 Hours

Deduplication Period

1 Day

Required Data

  • Requires one of the following data sources:
    • Windows Event Collector
      OR
    • XDR Agent with eXtended Threat Hunting (XTH)

Detection Modules

Identity Threat Module

Detector Tags

ATT&CK Tactic

Exfiltration (TA0010)

ATT&CK Technique

Exfiltration Over Physical Medium (T1052)

Severity

Informational

Description

A user printed an unusual number of files. This may be indicative of malicious activity and an attempt to exfiltrate data.

Attacker's Goals

In an attempt to exfiltrate data, a malicious insider might print an unusual number of files.

Investigative actions

Check for any other suspicious activity related to the host and the user involved in the alert.