An unusual archive file creation by a user
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
3 Days
Required Data
XDR Agent with eXtended Threat Hunting (XTH)
Detection Modules
Identity Threat Module
ATT&CK Tactic
Collection (TA0009)
ATT&CK Technique
Archive Collected Data: Archive via Utility (T1560.001), Data Staged (T1074)
Severity
Informational
Description
An archive file was created by a user who doesn't usually create such files. This might indicate an attempt to stage data before exfiltration.
Attacker's Goals
Stage data on an endpoint in the organization.
Investigative actions
Check for any other suspicious activity related to the host and the user involved in the alert.
Variations
PreviousAn unsigned process created scheduled task and performed an injection
NextAn unusual cloud identity was granted permissions to a BigQuery resource
Was this helpful?
