Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

12 detectors match the current filters. tactic: TA0009 ✕ technique: T1560 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
BIOC 7z.exe execution with password protection parameters 7z.exe was executed with parameters indicating password protection of the output file. Informational Platform Analytics Process execution Collection
Analytics BIOC A user created an abnormal password-protected archive A user created an abnormal password-protected archive using an archive program. Informational Identity Threat Detection (ITDR) XDR Agent with eXtended Threat Hunting (XTH) Collection
Analytics BIOC An unusual archive file creation by a user An archive file was created by a user who doesn't usually create such files. This might indicate an attempt to stage data before exfiltration. Informational Identity Threat Detection (ITDR) XDR Agent with eXtended Threat Hunting (XTH) Collection
BIOC Command-line creation of a RAR archive Compression of data into a RAR archive using the rar.exe utility. Informational Platform Analytics Process execution Collection
BIOC Compressed archive created using tar Attackers may use the tar built-in tool to stage a file for exfiltration. Informational Platform Analytics Process execution Collection
Analytics BIOC Compressing data using python Usage of a Python module to compress files. Low Platform Analytics XDR Agent Collection
BIOC Encrypted zip archive creation Attackers may stage information for exfiltration by encrypting it beforehand in a zip archive. Informational Platform Analytics Process execution Collection
Analytics Massive file compression by user Multiple archive files were created by a user. This might indicate an attempt to stage data before exfiltration. Informational Identity Threat Detection (ITDR) XDR Agent with eXtended Threat Hunting (XTH) Collection
BIOC Rar.exe execution with password protection parameters Rar.exe was executed with parameters indicating password protection of the output file. Informational Platform Analytics Process execution Collection
Analytics BIOC Unusual compressed file password protection An adversary might compress sensitive files with password protection to bypass security mitigations when attempting to exfiltrate them. Low Platform Analytics XDR Agent Collection
Analytics User collected remote shared files in an archive Multiple files from remote shares were archived in a local file. This may indicate collection of data and staging before exfiltration. Low Identity Threat Detection (ITDR) XDR Agent with eXtended Threat Hunting (XTH) Collection
BIOC Wzzip.exe execution with password protection parameters Wzzip.exe was executed with parameters indicating password protection of the output file. Informational Platform Analytics Process execution Collection