All incidents
MediumResolvedINC-E9C997

Bulk finance document collection followed by 1.2 GB egress

hlindqvist read 1,284 documents from the Finance share against a baseline of 14 per day, then transferred 1.2 GB to an external file-transfer service with no prior traffic history.

Opened 9d ago · 2026-09-03 13:40:29Z

Risk score
58
Moderate
Response target
Missed by 5.6h
24h target
Export report

Attack timeline

2 correlated events, oldest first.

  1. 01 / Anomalous File AccessMedium

    Principal hlindqvist read 1,284 documents from \\WIN-FS02\Finance in 9 minutes (baseline: 14/day)

    WIN-FS02user hlindqvistsrc 10.4.12.28host WIN-FS02
  2. 02 / Data EgressMedium

    allow tcp 10.4.12.28:49881 -> 104.28.211.19:443 bytes_out=1284739584 sni="upload.filetransfer.example" — destination unseen in prior 30 days

    Palo Alto Edgeuser hlindqvistsrc 10.4.12.28

Case notes

Analyst commentary recorded against this incident.

Cmd + Enter to save
  • ·2026-09-03 14:45Z

    Reached the user directly. hlindqvist is preparing the FY26 audit pack and was asked by Finance leadership to send it to the external auditor, who uses this transfer service.

  • ·2026-09-03 13:55Z

    Confirmed the engagement with the audit sponsor and matched the destination against the auditor's documented transfer domain. Closing as authorised business activity. Raising a separate hygiene ticket: this transfer should have gone through the sanctioned DLP-inspected channel, and the destination is now baselined so a repeat will not alert.

Case detail

Status
Resolved
Severity
Medium
Risk
58
Assignee
Analyst
Opened
2026-09-03 13:40Z
Last updated
7d ago

One-click containment

Automations targeted at this incident's own evidence.

Response playbook

Procedures worked step by step, with each completion recorded.

No playbook attached. Attaching one records each step as it is completed, so progress survives a shift change.

Attach a playbook

Containment

Runs in simulation. Nothing contacts a production control plane; every attempt is recorded.

Disable account
hlindqvist
Revoke active sessions
hlindqvist
Block source address
10.4.12.28
Isolate host
WIN-FS02

Response history

Actions already taken on this case.

No actions taken

No automated analysis

This case was opened without a generated narrative. Analysis is produced at triage time when an AI provider is configured in settings.