T1560 Archive Collected Data
An adversary may compress and/or encrypt data that is collected prior to exfiltration. Compressing the data can help to obfuscate the collected data and minimize the amount of data sent over the network.(Citation: DOJ GRU Indictment Jul 2018) Encryption can be used to hide information that is being exfiltrated from detection or make exfiltration less conspicuous upon inspection by a defender.…
Who uses it · with stories on Jábega
Sigma rules to hunt it
- APT31 Judgement Panda Activitycriticaltest · windows
- Conti NTDS Exfiltration Commandhightest · windows
- Rar Usage with Password and Compression Levelhightest · windows
- Suspicious Manipulation Of Default Accounts Via Net.EXEhightest · windows
- LiteLLM / TeamPCP Supply Chain Attack Indicatorshighexperimental · linux
- 7Zip Compressing Dump Filesmediumtest · windows
- Compress Data and Lock With Password for Exfiltration With 7-ZIPmediumtest · windows
- Compress Data and Lock With Password for Exfiltration With WINZIPmediumtest · windows
- Disk Image Mounting Via Hdiutil - MacOSmediumtest · macos
- WinRAR Execution in Non-Standard Foldermediumtest · windows
- Winrar Compressing Dump Filesmediumtest · windows
Rules from SigmaHQ · Detection Rule License 1.1. Technique from MITRE ATT&CK®.