Analytics BIOC
Informational
✕
A user created an abnormal password-protected archive
A user created an abnormal password-protected archive using an archive program.
- Module:
- Identity Threat Detection (ITDR)
- Licensed by:
- Identity Threat Detection (ITDR)
- Data source:
- XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Collection (TA0009)
ATT&CK techniques: Archive Collected Data: Archive via Utility (T1560.001) Data Staged (T1074)
Attacker's goals:
Collect data and stage it on an endpoint in the organization.
Investigative actions:
Check whether the command line executed is normal for the process and user performing it. Check whether the process that created the archive creates network connections as well. Check whether other users in the organization used the same process for password-protected archive file creation.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day