Legitimate Application Dropped Archive (654fcc6d-840d-4844-9b07-2c3300e54a26)
Detects programs on a Windows system that should not write an archive to disk
Cluster A | Galaxy A | Cluster B | Galaxy B | Level |
---|---|---|---|---|
Legitimate Application Dropped Archive (654fcc6d-840d-4844-9b07-2c3300e54a26) | Sigma-Rules | System Binary Proxy Execution - T1218 (457c7820-d331-465a-915e-42f85500ccc4) | Attack Pattern | 1 |