Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Collection/ T1074.001

T1074.001Local Data Staging

T1074.001 — Local Data Staging is a MITRE ATT&CK technique in the Collection tactic. Clankerusecase tracks 10 detection use cases covering it and 11 threat-intel articles citing it.

Collection
View on the matrix → Filter Detection Library MITRE official spec ↗
10Use cases
11Articles
0Sub-techniques
1Tactic

Use cases covering this technique (10)

Shai-Hulud 2 Exfiltration Artifact Files ESCU actions · alerting P [LLM] Windchill filesystem-enumeration artifact flst.txt written by web tier (CVE-2026-12569 discovery) Bespoke actions · hunting DSΣPDDCS [LLM] CAV3RN AzureCommunication.dll config file 'logAzure.txt' written to disk Bespoke install · alerting DSΣPDDCS [LLM] GoSerpent ThumbcacheService staging DB (thumbcache_605a.db) written to C:\Users\Public Bespoke actions · alerting DSΣPDDCS [LLM] GoSerpent 7-Zip archiving with hardcoded campaign password @vx0a9n5W2M0c3D6.# Bespoke actions · alerting DSΣPDDCS [LLM] Password-protected RAR staging of data for exfiltration (-hp) Bespoke actions · hunting DSΣPDDCS [LLM] node.js process staging credential dump in nt-* temp directory Bespoke actions · hunting DSΣPDDCS [LLM] SlimAgent keylogger HTML log artefact written to disk (Xagent-lineage colour scheme) Bespoke actions · hunting DSPDDCS [LLM] MuddyWater CE-Notes / LP-Notes / Blub stealer staging-file writes Bespoke actions · alerting DSΣPDDCS [LLM] Nx s1ngularity inventory file written to /tmp (inventory.txt / inventory.txt.bak) Bespoke actions · alerting DSΣPDDCS

Articles citing this technique (11)