Copy a user's GnuPG directory with rsync
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent
ATT&CK Tactic
Credential Access (TA0006)
ATT&CK Technique
Unsecured Credentials: Private Keys (T1552.004)
Severity
Low
Description
Copy a user's GnuPG (.gnupg) directory on to a staging folder using the 'find' and 'rsync' commands.
Attacker's Goals
Adversaries may use the rsync tool to exfiltrate secrets.
Investigative actions
Check whether the executing process is benign and if this was a desired behavior as part of its normal execution flow.
Was this helpful?
