Name:Email files written outside of the Outlook directory id:8d52cf03-ba25-4101-aa78-07994aed4f74 version:14 date:None author:Bhavin Patel, Splunk status:production type:Anomaly Description:The following analytic detects email files (.pst or .ost) being created outside the standard Outlook directories.
It leverages the Endpoint.Filesystem data model to identify file creation events and filters for email files not located in "C:\Users\*\My Documents\Outlook Files\*" or "C:\Users\*\AppData\Local\Microsoft\Outlook*".
This activity is significant as it may indicate data exfiltration or unauthorized access to email data.
If confirmed malicious, an attacker could potentially access sensitive email content, leading to data breaches or further exploitation within the network. Data_source:
-Sysmon EventID 11
search:| tstats `security_content_summariesonly` count values(Filesystem.file_path) as file_path min(_time) as firstTime max(_time) as lastTime
FROM datamodel=Endpoint.Filesystem WHERE
Filesystem.action IN ( "created", "modified" ) Filesystem.file_name IN ( "*.pst", "*.ost" ) NOT Filesystem.file_path IN ( "C:\\Users\\*\\My Documents\\Outlook Files\\*", "C:\\Users\\*\\AppData\\Local\\Microsoft\\Outlook*" )
how_to_implement:To successfully implement this search, you must be ingesting data that records the file-system activity from your hosts to populate the Endpoint.Filesystem data model node. This is typically populated via endpoint detection-and-response product, such as Carbon Black, or by other endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report file-system reads and writes. known_false_positives:Administrators and users sometimes prefer backing up their email data by moving the email files into a different folder. These attempts will be detected by the search.
You should confirm that the activity is legitimate and modify the search to add exclusions, as necessary. References: drilldown_searches:
: analytic_story:['Collection and Staging']