Skip to content

Latest commit

 

History

History
6 lines (6 loc) · 343 Bytes

An unusual archive file creation by a user.md

File metadata and controls

6 lines (6 loc) · 343 Bytes

Description

An archive file was created by a user who doesn't usually create such files. This might indicate an attempt to stage data before exfiltration.

Attacker's Goals

Stage data on an endpoint in the organization.

Investigative Actions

Check for any other suspicious activity related to the host and the user involved in the alert.