Suspicious data encryption
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent
ATT&CK Tactic
Impact (TA0040), Stealth (TA0005)
ATT&CK Technique
Data Encrypted for Impact (T1486), Obfuscated Files or Information: Encrypted/Encoded File (T1027.013)
Severity
Low
Description
Known applications were used to encrypt data within a machine's local file system.
Attacker's Goals
Damage or hide data on the local file system.
Investigative actions
Check if the action was done using an automation service.
Check if there are any other suspicious activities originated from the same machine/executing user.
PreviousSuspicious curl user agent
NextSuspicious disablement of the Windows Firewall using PowerShell commands
Was this helpful?
