APT3
|
Step
|
ATT&CK Pattern
|
Detection Type |
Detection Note |
|
19.B.1.1
|
|
|
Telemetry showed execution of recycler.exe with full command-line arguments, including -hp flag, indicating compression and encryption was used with a WinRAR utility.
|
|
19.B.1.2
|
|
|
Telemetry showed execution of recycler.exe with full command-line arguments, including -hp flag, indicating compression and encryption was used with a WinRAR utility.
|
|
Empire: Executed binary (recycler.exe) created compressed archive (old.rar) of previously collected file
-
Vendor stated alert logic exists for many files being accessed in a short period of time, which was not triggered in the evaluation because only one file was accessed.
Empire: Executed binary (recycler.exe) created encrypted archive (old.rar) of previously collected file
-
Vendor stated alert logic exists for many files being accessed in a short period of time, which was not triggered in the evaluation because only one file was accessed.