User collected remote shared files in an archive
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
1 Hour
Deduplication Period
1 Day
Required Data
XDR Agent with eXtended Threat Hunting (XTH)
Detection Modules
Identity Threat Module
ATT&CK Tactic
Collection (TA0009)
ATT&CK Technique
Archive Collected Data: Archive via Utility (T1560.001), Data Staged (T1074)
Severity
Low
Description
Multiple files from remote shares were archived in a local file. This may indicate collection of data and staging before exfiltration.
Attacker's Goals
Collect data and stage it on an endpoint in the organization.
Investigative actions
Check whether the process that created the archive creates network connections as well.
Check whether other users in the organization used the same process for remote archive file activity.
PreviousUser attempted to connect from a suspicious country
NextUser discovery via WMI query execution
Was this helpful?
