Analytics BIOC Low

Suspicious data encryption

Known applications were used to encrypt data within a machine's local file system.

Module:
Platform Analytics
Data source:
XDR Agent
ATT&CK tactics: Impact (TA0040) Defense Evasion (TA0005)
ATT&CK techniques: Data Encrypted for Impact (T1486) Obfuscated Files or Information: Encrypted/Encoded File (T1027.013)
Attacker's goals:

Damage or hide data on the local file system.

Investigative actions:

Check if the action was done using an automation service. Check if there are any other suspicious activities originated from the same machine/executing user.

Test period:
N/A (single event)
Deduplication:
1 Day