Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Collection/ T1074.001

T1074.001Local Data Staging

T1074.001 — Local Data Staging is a MITRE ATT&CK technique in the Collection tactic. Clankerusecase tracks 8 detection use cases covering it and 9 threat-intel articles citing it.

Collection
View on the matrix → Filter Detection Library MITRE official spec ↗
8Use cases
9Articles
0Sub-techniques
1Tactic

Use cases covering this technique (8)

Shai-Hulud 2 Exfiltration Artifact Files ESCU actions · alerting P [LLM] ZIP archive named with public-IPv4 pattern created in user-writable directory (Gremlin Stealer) Bespoke actions · hunting DSΣPDDCS [LLM] node.js process staging credential dump in nt-* temp directory Bespoke actions · hunting DSΣPDDCS [LLM] SlimAgent keylogger HTML log artefact written to disk (Xagent-lineage colour scheme) Bespoke actions · hunting DSPDDCS [LLM] s1ngularity collection artifact — `/tmp/inventory.txt` written by node/npm on runner Bespoke actions · alerting DSΣPDDCS [LLM] MuddyWater CE-Notes / LP-Notes / Blub stealer staging-file writes Bespoke actions · alerting DSΣPDDCS [LLM] s1ngularity nx: /tmp/inventory.txt staging file created on host Bespoke actions · alerting DSΣPDD [LLM] Nx s1ngularity inventory file written to /tmp (inventory.txt / inventory.txt.bak) Bespoke actions · alerting DSΣPDDCS

Articles citing this technique (9)