Data Exfiltration / Large file uploads

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Data Exfiltration / Large file uploads

L2 Linker

Hello community,

 

I was wondering if anyone found an efficient query to look for data exfiltration/large file uploads?

 

I'm looking more from a threat hunting perspective, where I would want to trace one or multiple file being uploaded to a remote destination.

 

Right now the only way I've found is to correlate file read actions in the same timeframe of a network session to a remote site. But this isn't 100% reliable way and that wouldn't hold in court as evidence since at the end of the day it is just a file read.

 

Anyone has any suggestions?

 

Thank you

 

Luc D.

6 REPLIES 6

L2 Linker

Please check out

1. XQL Query library: you can search for "upload" to see all related queries like Large FTP Sessions, Curl uploading more than 1MB etc

 

2. XDR Analytics currently do large uploads computation if there is applicable data. It triggers when endpoint transferred an excessive amount of data to an unpopular destination.

 

Please check-out:

https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-analytics-alert-reference/cortex-xdr-...

https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-analytics-alert-reference/cortex-xdr-...

https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-analytics-alert-reference/cortex-xdr-...

https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-analytics-alert-reference/cortex-xdr-...

You can get more interesting data if you have enhanced application logging from NGFW. Sample fields (like session upload) from the session detail is attached.

Hi Malalade,

 

Thank you for the info, but this doesn't really answer my question which is how can you identify what data was uploaded.

 

Let me know if you can think of anything. Right now I go with file reads from the process generating the large upload, but this is far from a 100% science, was wondering if others figured out other more efficient ways.

 

Thanks

 

Luc

 

 

Were you able to find a solution? Having a similar issue where I want to pull all large file uploads

Hi @MrDuck, @Luc_Desaulniers 

what @malalade answered with he links to the alerts is how you will see the uploads and be able to identify which uploads were those since this information will be in the alerts and incidents created. 

 

KR,

Luis

While I appreciate the answer that was provided, it doesn't answer the original question, which is how do you determine what data(files) were actually uploaded.

 

I know how to see the alerts, but those alerts don't contain file names/locations. Only session details, which I usually use to kind of figure out through the file reads actions during the timeframe, but was wondering if others found better ways?

L0 Member

@Luc_Desaulniers Did you find a way to achieve what you describe? I have the same questions here.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!