Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0261 — Detection of Local Data Staging Prior to Exfiltration
DET0261

Detection of Local Data Staging Prior to Exfiltration

4 analytic(s) · 1 technique(s) detected

Analytics

4
AN0724 Analytic 0724
Windows

Detects file reads across locations followed by writes to temp or staging directories, often compressed or encrypted, indicating local staging behavior.

WinEventLog:Sysmon EventCode=11 WinEventLog:Sysmon EventCode=1 WinEventLog:Security EventCode=4663, 4670, 4656
[StagingDirList] Paths such as C:\Temp, C:\Windows\Tasks, etc.
[ArchivingToolPatterns] Matches to 7z.exe, rar.exe, zip.exe, or custom scripts.
[TimeWindow] How long to correlate file reads followed by compression.
AN0725 Analytic 0725
Linux

Detects aggregation of files from different directories into /tmp, /mnt, or user-specified directories with archiving tools like tar or gzip.

auditd:SYSCALL open auditd:SYSCALL execve
[StagingDirs] e.g., /tmp, /var/tmp, custom user dirs
[ArchiveUtilities] tar, gzip, zip, 7z
[UserThreshold] Number of files or size written in short time
AN0726 Analytic 0726
macOS

Detects staged data aggregated in /Users/Shared, /private/tmp with compression tools like ditto or zip, initiated via Terminal or AppleScript.

macos:unifiedlog file events macos:unifiedlog exec logs
[StagingTargets] Shared dirs commonly abused for local collection
[CompressionBinaries] zip, tar, ditto
[TimeWindow] Seconds/minutes between source file read and output staging write
AN0727 Analytic 0727
ESXi

Detects local staging behavior via snapshot creation or files written into VMFS partitions by scripts or unauthorized shell access.

esxi:vmkernel snapshot create/write events esxi:shell CLI usage logs
[SnapshotThreshold] Rapid creation or deletion of snapshots
[CLIInvoker] Unexpected CLI/script invocation outside maintenance windows
[VMFSWriteRate] Volume of data written locally in short time

Detected Techniques

1

Details

MITRE ID
DET0261
STIX ID
x-mitre-detection-strategy--e91165c5-e850-465e-9042-6ba82478b522
Analytics
4
Techniques Detected
1
By Tactic
Collection
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.