Skip to content

Latest commit

 

History

History
8 lines (8 loc) · 490 Bytes

A user created an abnormal password-protected archive.md

File metadata and controls

8 lines (8 loc) · 490 Bytes

Description

A user created an abnormal password-protected archive using an archive program

Attacker's Goals

Collect data and stage it on an endpoint in the organization.

Investigative Actions

Check whether the command line executed is normal for the process and user performing it. Check whether the process that created the archive creates network connections as well. Check whether other users in the organization used the same process for password-protected archive file creation.