This commit is contained in:
patel-bhavin
2022-02-28 17:44:03 -08:00
parent 7752620e90
commit 7f2e056b3e
@@ -6,7 +6,7 @@ author: Teoderick Contreras, Splunk
type: Hunting
datamodel:
- Endpoint
description: This search is to detect a suspicious 7z process with commandline pointing
description: This detection search is to detect a suspicious 7z process with commandline pointing
to SMB network share. This technique was seen in CONTI LEAK tools where it use 7z
to archive a sensitive files and place it in network share tmp folder. This search
is a good hunting query that may give analyst a hint why specific user try to archive