For the complete documentation index, see llms.txt. This page is also available as Markdown.

User collected remote shared files in an archive

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

1 Hour

Deduplication Period

1 Day

Required Data

XDR Agent with eXtended Threat Hunting (XTH)

Detection Modules

Identity Threat Module

ATT&CK Tactic

Collection (TA0009)

ATT&CK Technique

Archive Collected Data: Archive via Utility (T1560.001), Data Staged (T1074)

Severity

Low

Description

Multiple files from remote shares were archived in a local file. This may indicate collection of data and staging before exfiltration.

Attacker's Goals

Collect data and stage it on an endpoint in the organization.

Investigative actions

  • Check whether the process that created the archive creates network connections as well.

  • Check whether other users in the organization used the same process for remote archive file activity.

Was this helpful?