Skip to content

Latest commit

 

History

History
9 lines (9 loc) · 548 Bytes

A user took numerous screenshots.md

File metadata and controls

9 lines (9 loc) · 548 Bytes

Description

A user took numerous screenshots. A valuable organization's information may have been collected in this way

Attacker's Goals

Collect data and stage it on an endpoint in the organization.

Investigative Actions

Check whether this activity fits the user profile. Check for any other suspicious activity related to the host and the user involved in the alert. Check if there was a suspicious file upload following the massive screenshot activity. Check whether other users in the organization used the same process for file activity.