A user created an abnormal password-protected archive
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent with eXtended Threat Hunting (XTH)
Detection Modules
Identity Threat Module
ATT&CK Tactic
Collection (TA0009)
ATT&CK Technique
Archive Collected Data: Archive via Utility (T1560.001), Data Staged (T1074)
Severity
Informational
Description
A user created an abnormal password-protected archive using an archive program.
Attacker's Goals
Collect data and stage it on an endpoint in the organization.
Investigative actions
Check whether the command line executed is normal for the process and user performing it.
Check whether the process that created the archive creates network connections as well.
Check whether other users in the organization used the same process for password-protected archive file creation.
Was this helpful?
