T1560.001Archive via Utility
T1560.001 — Archive via Utility is a MITRE ATT&CK technique in the Collection tactic. Clankerusecase tracks 14 detection use cases covering it and 8 threat-intel articles citing it.
Collection
14Use cases
8Articles
0Sub-techniques
1Tactic
↑ Parent technique: T1560 · Archive Collected Data
Use cases covering this technique (14)
7zip CommandLine To SMB Share Path Anomalous usage of 7zip Detect Renamed 7-Zip Detect Renamed WinRAR IcedID Exfiltrated Archived File Creation Windows Archive Collected Data via Rar [LLM] PeopleSoft lateral-movement script — *_fanout.sh execution and zstd compression chain [LLM] ZIP archive named with public-IPv4 pattern created in user-writable directory (Gremlin Stealer) [LLM] node.js process staging credential dump in nt-* temp directory [LLM] Stage-3 exfil archive trin.tar.gz POST via curl --data-binary [LLM] Credential archive staging — trin.tar.gz created by python process [LLM] TeamPCP exfiltration archive tpcp.tar.gz created on disk [LLM] TeamPCP exfiltration archive — tpcp.tar.gz file creation on host [LLM] Exfil staging artefacts: session.key, payload.enc, session.key.enc, tpcp.tar.gz in tempArticles citing this technique (8)
crit ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities art-37
crit Malicious node-ipc versions published to npm in suspected maintainer account compromise art-284