Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0495 — Detection Strategy for Financial Theft
DET0495

Detection Strategy for Financial Theft

5 analytic(s) · 1 technique(s) detected

Analytics

5
AN1361 Analytic 1361
Windows

Monitor for anomalous access to financial applications, browser-based banking sessions, or enterprise ERP systems from Windows endpoints. Detect mass emailing of payment instructions, sudden rule changes in Outlook for financial staff, or use of clipboard data exfiltration tied to cryptocurrency wallet addresses.

WinEventLog:Security EventCode=4624, 4648 WinEventLog:Sysmon EventCode=1
[FinanceAppList] Baseline of finance-related executables or ERP processes to monitor closely.
[HighRiskAccounts] Accounts belonging to finance, treasury, or executives that should be monitored with higher sensitivity.
AN1362 Analytic 1362
Linux

Monitor server and endpoint logs for unusual outbound network connections to cryptocurrency nodes, unauthorized scripts accessing financial systems, or automation targeting payment file formats. Detect curl/wget activity aimed at exfiltrating transaction data or credentials from financial apps.

auditd:SYSCALL execve: Execution of curl, wget, or custom scripts accessing financial endpoints linux:syslog Authentication attempts into finance-related servers from unusual IPs or times
[KnownFinanceIPs] Whitelisted IPs for finance-related traffic to reduce noise.
AN1363 Analytic 1363
macOS

Monitor unified logs for access to payment applications, browser plug-ins, or Apple Pay services from non-standard processes. Detect anomalous use of Automator scripts or keychain extraction targeting financial account credentials.

macos:unifiedlog Non-standard processes invoking financial applications or payment APIs macos:unifiedlog Anomalous keychain access attempts targeting payment credentials
[MonitoredApps] Financial or payment applications to explicitly monitor for unauthorized use.
AN1364 Analytic 1364
SaaS

Monitor SaaS financial systems (e.g., QuickBooks, Workday, SAP S/4HANA cloud) for unauthorized access, rule changes, or mass export of financial data. Detect anomalous transfers initiated via SaaS APIs or new MFA-disabled logins targeting finance apps.

saas:finance Transaction/Transfer: Unusual or large transactions initiated outside business hours or by unusual accounts
[TransactionThreshold] Customizable monetary threshold above which financial transactions should be flagged.
AN1365 Analytic 1365
Office Suite

Monitor email and document management systems for fraudulent invoices, impersonation of vendors, or BEC-style payment redirections. Detect abnormal editing of invoice templates, or emails containing known fraud language combined with attachment delivery.

m365:unified MailSend: Outlook messages with suspicious subject/body terms (e.g., urgent payment, wire transfer) targeting finance teams m365:office Anomalous editing of invoice or payment document templates
[FraudTerms] Adjustable keyword list for email and document fraud detection.

Detected Techniques

1

Details

MITRE ID
DET0495
STIX ID
x-mitre-detection-strategy--e767f434-dda3-41fe-a9ea-e7aaae251e61
Analytics
5
Techniques Detected
1
By Tactic
Impact
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.