Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. technique: T1560 ✕
Download CSV Show ATT&CK heatmapMassive file compression by user Informational Identity Threat Module
Multiple archive files were created by a user. This might indicate an attempt to stage data before exfiltration.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- 3 Hours
- Deduplication:
- 1 Day
ATT&CK tactics: Collection (TA0009)ATT&CK techniques: Archive Collected Data: Archive via Utility (T1560.001) Data Staged (T1074)Required data: XDR Agent with eXtended Threat Hunting (XTH)Attacker's goals: Stage data on an endpoint in the organization.Investigative actions: Check for any other suspicious activity related to the host and the user involved in the alert.