Skip to content

Hide Navigation Hide TOC

7Zip Compressing Dump Files (ec570e53-4c76-45a9-804d-dc3f355ff7a7)

Detects execution of 7z in order to compress a file with a ".dmp"/".dump" extension, which could be a step in a process of dump file exfiltration.

Cluster A Galaxy A Cluster B Galaxy B Level
Archive via Utility - T1560.001 (00f90846-cbd1-4fc5-9233-df5c2bf2a662) Attack Pattern 7Zip Compressing Dump Files (ec570e53-4c76-45a9-804d-dc3f355ff7a7) Sigma-Rules 1
Archive Collected Data - T1560 (53ac20cd-aca3-406e-9aa0-9fc7fdc60a5a) Attack Pattern Archive via Utility - T1560.001 (00f90846-cbd1-4fc5-9233-df5c2bf2a662) Attack Pattern 2