T1074.001Local Data Staging
T1074.001 — Local Data Staging is a MITRE ATT&CK technique in the Collection tactic. Clankerusecase tracks 10 detection use cases covering it and 11 threat-intel articles citing it.
Collection
10Use cases
11Articles
0Sub-techniques
1Tactic
↑ Parent technique: T1074 · Data Staged
Use cases covering this technique (10)
Shai-Hulud 2 Exfiltration Artifact Files [LLM] Windchill filesystem-enumeration artifact flst.txt written by web tier (CVE-2026-12569 discovery) [LLM] CAV3RN AzureCommunication.dll config file 'logAzure.txt' written to disk [LLM] GoSerpent ThumbcacheService staging DB (thumbcache_605a.db) written to C:\Users\Public [LLM] GoSerpent 7-Zip archiving with hardcoded campaign password @vx0a9n5W2M0c3D6.# [LLM] Password-protected RAR staging of data for exfiltration (-hp) [LLM] node.js process staging credential dump in nt-* temp directory [LLM] SlimAgent keylogger HTML log artefact written to disk (Xagent-lineage colour scheme) [LLM] MuddyWater CE-Notes / LP-Notes / Blub stealer staging-file writes [LLM] Nx s1ngularity inventory file written to /tmp (inventory.txt / inventory.txt.bak)Articles citing this technique (11)
crit Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE art-90
high GoSerpent: a persistent threat evolves with sophisticated data collection and exfiltration art-161