Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Collection/ T1560.001

T1560.001Archive via Utility

T1560.001 — Archive via Utility is a MITRE ATT&CK technique in the Collection tactic. Clankerusecase tracks 16 detection use cases covering it and 10 threat-intel articles citing it.

Collection
View on the matrix → Filter Detection Library MITRE official spec ↗
16Use cases
10Articles
0Sub-techniques
1Tactic

Use cases covering this technique (16)

7zip CommandLine To SMB Share Path ESCU actions · hunting P Anomalous usage of 7zip ESCU actions · hunting P Detect Renamed 7-Zip ESCU actions · hunting P Detect Renamed WinRAR ESCU actions · hunting P IcedID Exfiltrated Archived File Creation ESCU actions · hunting P Windows Archive Collected Data via Rar ESCU actions · hunting P [LLM] GoSerpent 7-Zip archiving with hardcoded campaign password @vx0a9n5W2M0c3D6.# Bespoke actions · alerting DSΣPDDCS [LLM] Password-protected RAR staging of data for exfiltration (-hp) Bespoke actions · hunting DSΣPDDCS [LLM] macOS.Gaslight keychain theft + collected_data.zip staging Bespoke actions · alerting DSΣPCS [LLM] s1ngularity Nx compromise: results.b64 credential dump written on developer host Bespoke actions · alerting DSΣPDDCS [LLM] node.js process staging credential dump in nt-* temp directory Bespoke actions · hunting DSΣPDDCS [LLM] Stage-3 exfil archive trin.tar.gz POST via curl --data-binary Bespoke actions · alerting DSΣPDDCS [LLM] Credential archive staging — trin.tar.gz created by python process Bespoke actions · alerting DSΣPDDCS [LLM] TeamPCP exfiltration archive tpcp.tar.gz created on disk Bespoke actions · alerting DSΣPDDCS [LLM] TeamPCP exfiltration archive — tpcp.tar.gz file creation on host Bespoke actions · alerting DSΣPDD [LLM] Exfil staging artefacts: session.key, payload.enc, session.key.enc, tpcp.tar.gz in temp Bespoke actions · alerting DSΣPDDCS

Articles citing this technique (10)