From 7f2e056b3eef831ffe4708e19ef2530ea9bc44a8 Mon Sep 17 00:00:00 2001 From: patel-bhavin Date: Mon, 28 Feb 2022 17:44:03 -0800 Subject: [PATCH] testing --- detections/endpoint/7zip_commandline_to_smb_share_path.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/detections/endpoint/7zip_commandline_to_smb_share_path.yml b/detections/endpoint/7zip_commandline_to_smb_share_path.yml index 59f9728be9..9f267c0507 100644 --- a/detections/endpoint/7zip_commandline_to_smb_share_path.yml +++ b/detections/endpoint/7zip_commandline_to_smb_share_path.yml @@ -6,7 +6,7 @@ author: Teoderick Contreras, Splunk type: Hunting datamodel: - Endpoint -description: This search is to detect a suspicious 7z process with commandline pointing +description: This detection search is to detect a suspicious 7z process with commandline pointing to SMB network share. This technique was seen in CONTI LEAK tools where it use 7z to archive a sensitive files and place it in network share tmp folder. This search is a good hunting query that may give analyst a hint why specific user try to archive