Analytics BIOC
Low
✕
Suspicious data encryption
Known applications were used to encrypt data within a machine's local file system.
- Module:
- Platform Analytics
- Data source:
- XDR Agent
ATT&CK tactics: Impact (TA0040) Defense Evasion (TA0005)
ATT&CK techniques: Data Encrypted for Impact (T1486) Obfuscated Files or Information: Encrypted/Encoded File (T1027.013)
Attacker's goals:
Damage or hide data on the local file system.
Investigative actions:
Check if the action was done using an automation service. Check if there are any other suspicious activities originated from the same machine/executing user.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day