T1074 – Data Staged (Sysmon Detection)
Sysmon Alert Details Alert ID: SYSMON-DATA-STAGED-1074-7842 Alert Time: 2024-02-28 14:15:33 EST Severity: HIGH (85/100) Source: Sysmon (Event ID 11 – FileCreate) Rule: “Mass File Copy to Staging Directory” MITRE ATT&CK: T1074.001 – Data Staged: Local Data Staging Alert Details: Detection: Large number of files copied to a staging directory Host: ENG-WS-045 (Engineering Workstation) User: alexchen@company.com … Read more