File Hunter

Discover recently used files on a system and prepare a staging directory. Copy all of those discovered files to the staging directory then compress the directory to prepare it for exfiltration.
Authors:privateducky, khyberspache, mitre, w0rk3r

Execute this chain

Download Operator (1.7.0)
Learn about Operator

TTPs

Stage collected files
Find recent files
Create new directory
Compress staged directory

Tags

crown jewels, ransomware