Suspicious access to Unattended Panther files

Identifies suspicious to access to unattend.xml files where credentials are commonly stored within the Panther directory. Adversaries may search local file systems and remote file shares for files containing insecurely stored credentials.

Back to all rules