Cross-source coverage

T1657 / ATT&CK

Financial Theft

2 rules across 2 sources.

From MITRE ATT&CK 19.2

Adversaries may steal monetary resources from targets through extortion, social engineering, technical theft, or other methods aimed at their own financial gain at the expense of the availability of these resources for victims. Financial theft is the ultimate objective of several popular campaign types including extortion by ransomware, business email compromise (BEC) and fraud, "pig butchering," bank hacking, and exploiting cryptocurrency networks.

Adversaries may Compromise Accounts to conduct unauthorized transfers of funds. In the case of business email compromise or email fraud, an adversary may utilize Impersonation of a trusted entity. Once the social engineering is successful, victims can be deceived into sending money to financial accounts controlled by an adversary. This creates the potential for multiple victims (i.e., compromised accounts as well as the ultimate monetary loss) in incidents involving financial theft.

Extortion by ransomware may occur, for example, when an adversary demands payment from a victim after Data Encrypted for Impact and Exfiltration of data, followed by threatening to leak sensitive data to the public unless payment is made to the adversary. Adversaries may use dedicated leak sites to distribute victim data.

Due to the potentially immense business impact of financial theft, an adversary may abuse the possibility of financial theft and seeking monetary gain to divert attention from their true goals such as Data Destruction and business disruption.

Tactics
Impact
Platforms
Linux · macOS · Office Suite · SaaS · Windows
Telemetry
WinEventLog:SecurityWinEventLog:Sysmonauditd:SYSCALLlinux:syslogmacos:unifiedlogsaas:financem365:unifiedm365:office

How MITRE says to detect it DET0495

Detection Strategy for Financial Theft

Windows Analytic 1361

Monitor for anomalous access to financial applications, browser-based banking sessions, or enterprise ERP systems from Windows endpoints. Detect mass emailing of payment instructions, sudden rule changes in Outlook for financial staff, or use of clipboard data exfiltration tied to cryptocurrency wallet addresses.

  • WinEventLog:Security EventCode=4624, 4648
  • WinEventLog:Sysmon EventCode=1

Linux Analytic 1362

Monitor server and endpoint logs for unusual outbound network connections to cryptocurrency nodes, unauthorized scripts accessing financial systems, or automation targeting payment file formats. Detect curl/wget activity aimed at exfiltrating transaction data or credentials from financial apps.

  • auditd:SYSCALL execve: Execution of curl, wget, or custom scripts accessing financial endpoints
  • linux:syslog Authentication attempts into finance-related servers from unusual IPs or times

macOS Analytic 1363

Monitor unified logs for access to payment applications, browser plug-ins, or Apple Pay services from non-standard processes. Detect anomalous use of Automator scripts or keychain extraction targeting financial account credentials.

  • macos:unifiedlog Non-standard processes invoking financial applications or payment APIs
  • macos:unifiedlog Anomalous keychain access attempts targeting payment credentials

SaaS Analytic 1364

Monitor SaaS financial systems (e.g., QuickBooks, Workday, SAP S/4HANA cloud) for unauthorized access, rule changes, or mass export of financial data. Detect anomalous transfers initiated via SaaS APIs or new MFA-disabled logins targeting finance apps.

  • saas:finance Transaction/Transfer: Unusual or large transactions initiated outside business hours or by unusual accounts

Office Suite Analytic 1365

Monitor email and document management systems for fraudulent invoices, impersonation of vendors, or BEC-style payment redirections. Detect abnormal editing of invoice templates, or emails containing known fraud language combined with attachment delivery.

  • m365:unified MailSend: Outlook messages with suspicious subject/body terms (e.g., urgent payment, wire transfer) targeting finance teams
  • m365:office Anomalous editing of invoice or payment document templates

Bert-JanP/Hunting-Queries-Detection-Rules

1 rule
Detection Severity Format
Monitor ransomwarelive for companies of interest on ransowmare data leak sites (DLS) Undefined KQL

elastic/detection-rules

1 rule
Detection Severity Format
AWS S3 Bucket Enumeration or Brute Force Low Elastic TOML

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.