Name:High Frequency Copy Of Files In Network Share id:40925f12-4709-11ec-bb43-acde48001122 version:11 date:None author:Teoderick Contreras, Splunk status:production type:Anomaly Description:The following analytic detects a high frequency of file copying or moving within network shares, which may indicate potential data sabotage or exfiltration attempts.
It leverages Windows Security Event Logs (EventCode 5145) to monitor access to specific file types and network shares.
This activity is significant as it can reveal insider threats attempting to transfer classified or internal files, potentially leading to data breaches or evidence tampering.
If confirmed malicious, this behavior could result in unauthorized data access, data loss, or compromised sensitive information. Data_source:
``` We Select only write-related operations: 0x2 = WriteData (create/write file) 0x4 = AppendData (append to file) ```
| where (bit_and(AccessMask_, 2) != 0) OR (bit_and(AccessMask_, 4) != 0)
| bucket _time span=5m
``` Count write events per host, user and source IP within each time window ``` | stats values(RelativeTargetName) AS valRelativeTargetName values(ShareName) AS valShareName values(ObjectType) AS valObjectType values(AccessMask) AS valAccessMask values(src_port) AS valSrcPort values(SourceAddress) AS valSrcAddress count AS numFileWriteEvents BY dest _time EventCode src_user src_ip
``` Build a historical baseline for each destination host and user using the average and standard deviation of previous buckets ```
| eventstats avg(numFileWriteEvents) AS avgFileWriteEvents stdev(numFileWriteEvents) AS stdFileWriteEvents count AS numSlots BY dest EventCode src_user
how_to_implement:To successfully implement this search, you need to be ingesting Windows Security Event Logs with 5145 EventCode enabled. The Windows TA is also required. Also enable the object Audit access success/failure in your group policy. known_false_positives:This behavior may be seen in normal transfer of files within a network if network shares are commonly used for sharing documents. References: -https://attack.mitre.org/techniques/T1537/ -https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-10/security/threat-protection/auditing/event-5145#table-of-file-access-codes drilldown_searches: name:'View the detection results for - "$src_user$"' search:'%original_detection_search% | search src_user = "$src_user$"' earliest_offset:'$info_min_time$' latest_offset:'$info_max_time$' name:'View risk events for the last 7 days for - "$src_user$"' search:'| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$src_user$") | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' earliest_offset:'7d' latest_offset:'0' analytic_story:['Information Sabotage', 'Insider Threat', 'Hellcat Ransomware']