Analytics BIOC Low

Unusual compressed file password protection

An adversary might compress sensitive files with password protection to bypass security mitigations when attempting to exfiltrate them.

Module:
Platform Analytics
Data source:
XDR Agent
ATT&CK tactics: Collection (TA0009)
ATT&CK techniques: Archive Collected Data: Archive via Utility (T1560.001)
Detector tags: Kubernetes - AGENT Containers
Attacker's goals:

Exfiltrate or hide sensitive data.

Investigative actions:

Check if the action was done using an automation service. Check if there are any other suspicious activities originated from the same machine/executing user.

Test period:
N/A (single event)
Deduplication:
1 Day
1 variation:
  • Unusual compressed file password protection in a Kubernetes pod Low