During a nightly review, EDR shows a workstation created a 4 GB archive in a user's temporary folder at 02:15, followed by 3.8 GB outbound over TCP/443 to an IP contacted only once in the past 90 days. No malware detections occurred. Which indicator should the analyst prioritize?
Select an answer to reveal the explanation.
Short Explanation
Think of it like this: a big zip in a temp folder followed by a big upload is like stuffing a suitcase before leaving the building. You don't need malware to call it staging; the sequence tells the story. The trap is treating it as backup or policy noise instead of an exfiltration precursor.
Full Explanation
Large archives created in user-accessible locations shortly before unusually large outbound transfers are a classic precursor to exfiltration. The analyst should treat the archive creation as staging: the attacker or insider consolidates, compresses, and often obfuscates collected data to reduce transfer time and evade simple volume-based alerts. Correlating file-creation events, process lineage, destination reputation, and egress volume supports prioritizing containment.
A routine backup would normally originate from a backup service account, target approved storage, and follow a schedule or job record rather than appear in a temporary user folder followed by an ad hoc destination. An archive policy violation is a hygiene issue, not a priority security event unless it is tied to unauthorized egress or sensitive data movement. Persistence focuses on maintaining access through scheduled tasks, services, or registry modifications; it does not explain the observed compression and bulk network transfer, which are collection and exfiltration behaviors.
Exam caveat: The strongest indicator is the sequence of local staging followed by anomalous egress, not the absence of malware or the file extension alone. Operational check: Query EDR for the process that created the archive, identify the parent process and file access history, then confirm whether the destination is expected for that workload.