mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
testing
This commit is contained in:
@@ -6,7 +6,7 @@ author: Teoderick Contreras, Splunk
|
||||
type: Hunting
|
||||
datamodel:
|
||||
- Endpoint
|
||||
description: This search is to detect a suspicious 7z process with commandline pointing
|
||||
description: This detection search is to detect a suspicious 7z process with commandline pointing
|
||||
to SMB network share. This technique was seen in CONTI LEAK tools where it use 7z
|
||||
to archive a sensitive files and place it in network share tmp folder. This search
|
||||
is a good hunting query that may give analyst a hint why specific user try to archive
|
||||
|
||||
Reference in New Issue
Block a user