Unusual compressed file password protection
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent
Detector Tags
Kubernetes - AGENT, Containers
ATT&CK Tactic
Collection (TA0009)
ATT&CK Technique
Archive Collected Data: Archive via Utility (T1560.001)
Severity
Low
Description
An adversary might compress sensitive files with password protection to bypass security mitigations when attempting to exfiltrate them.
Attacker's Goals
Exfiltrate or hide sensitive data.
Investigative actions
Check if the action was done using an automation service.
Check if there are any other suspicious activities originated from the same machine/executing user.
Variations
PreviousUnusual cloud Instance Metadata Service (IMDS) access
NextUnusual Conditional Access operation for an identity
Was this helpful?
