Title:
Suspicious Access to Sensitive File Extensions
Status:
test
Description:Detects known sensitive file extensions accessed on a network share
References:
-Internal Research
Author: Samir Bousseaden
Date: 2019-04-03
modified:2025-10-17
Tags:
- -'attack.collection'
- -'attack.t1039'
Logsource:
- product: windows
- service: security
Detection:
selection:
EventID:
'5145'
RelativeTargetName|endswith:
-'.bak'
-'.dmp'
-'.edb'
-'.kirbi'
-'.msg'
-'.nsf'
-'.nst'
-'.oab'
-'.ost'
-'.pst'
-'.rdp'
condition:
selection
Falsepositives:
-Help Desk operator doing backup or re-imaging end user machine or backup software
-Users working with these data types or exchanging message files
Level:
medium