T1560 Archive Collected Data — ATT&CK Technique
An adversary may compress and/or encrypt data that is collected prior to exfiltration. Compressing the data can help to obfuscate the collected data and minimize the amount of data sent over the network. Encryption can be used to hide information that is being exfiltrated from detection or make exfiltration less conspicuous upon inspection by a defender. Both compression and encryption are done prior to exfiltration, and can be performed using a utility, 3rd party library, or custom method.
Detection coverage (7)
- Conti NTDS Exfiltration Command high
- Compress-Archive Cmdlet Execution low
- Compressed File Creation Via Tar.EXE low
- Compressed File Extraction Via Tar.EXE low
- Detect Certipy File Modifications
- Windows Archive Collected Data via Powershell
- Windows Archived Collected Data In TEMP Folder
Malware using this technique
- Chrommme
- Exaramel for Windows
- TAINTEDSCRIBE
- LoFiSe
- BloodHound
- ADVSTORESHELL
- MuddyViper
- Empire
- Bumblebee
- WellMail
- Cadelspy
- Spica
- LightNeuron
- Troll Stealer
- VERMIN
- LP-Notes
- ShimRatReporter
- XCSSET
- Gold Dragon
- KONNI
- Raccoon Stealer
- NETWIRE
- PowerLess
- Epic
- Remexi
- Kessel
- Zebrocy
- Lurid
- AppleSeed
- JumbledPath
- Backdoor.Oldrea
- BLUELIGHT
- FELIXROOT
- Dtrack
- RunningRAT
- Machete
- Agent Tesla
- Daserf
- Proton
- Pillowmint
- Aria-body
- Prikormka
- Lizar