- 필수 기능
- 시작하기
- Glossary
- 표준 속성
- Guides
- Agent
- 통합
- 개방형텔레메트리
- 개발자
- Administrator's Guide
- API
- Datadog Mobile App
- CoScreen
- Cloudcraft
- 앱 내
- 서비스 관리
- 인프라스트럭처
- 애플리케이션 성능
- APM
- Continuous Profiler
- 스팬 시각화
- 데이터 스트림 모니터링
- 데이터 작업 모니터링
- 디지털 경험
- 소프트웨어 제공
- 보안
- AI Observability
- 로그 관리
- 관리
",t};e.buildCustomizationMenuUi=t;function n(e){let t='
",t}function s(e){let n=e.filter.currentValue||e.filter.defaultValue,t='${e.filter.label}
`,e.filter.options.forEach(s=>{let o=s.id===n;t+=``}),t+="${e.filter.label}
`,t+=`Detects file transfer operations through ScreenConnect remote access software that may indicate unauthorized data movement.
This rule monitors ScreenConnect application events, where @evt.id
is 201
from the ScreenConnect
provider when @Event.EventData.Data
contains Transferred
, excluding legitimate elevated execution events. ScreenConnect is a legitimate remote access tool commonly used for IT support and system administration, but it can be abused by attackers for command and control activities and data exfiltration. The detection focuses on file transfer operations which may indicate unauthorized movement of sensitive data or deployment of malicious tools through the remote access session.
{{host}}
and determine if they represent legitimate business data or potentially malicious content.