Analytics Informational

Massive file compression by user

Multiple archive files were created by a user. This might indicate an attempt to stage data before exfiltration.

Module:
Identity Threat Detection (ITDR)
Licensed by:
Identity Threat Detection (ITDR)
Data source:
XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Collection (TA0009)
ATT&CK techniques: Archive Collected Data: Archive via Utility (T1560.001) Data Staged (T1074)
Attacker's goals:

Stage data on an endpoint in the organization.

Investigative actions:

Check for any other suspicious activity related to the host and the user involved in the alert.

Test period:
3 Hours
Deduplication:
1 Day