Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0438 — Detect Archiving via Custom Method (T1560.003)
DET0438

Detect Archiving via Custom Method (T1560.003)

3 analytic(s) · 1 technique(s) detected

Analytics

3
AN1213 Analytic 1213
Windows

Detects suspicious custom compression/encryption routines through anomalous script or binary execution that produces high-entropy files without standard archiving utilities. Correlates script execution, memory API usage (bitwise ops, CryptoAPI calls), and creation of archive-like files with uncommon headers.

WinEventLog:Security EventCode=4688 WinEventLog:Sysmon EventCode=11 WinEventLog:Sysmon EventCode=10
[EntropyThreshold] Minimum entropy level that flags suspicious custom archives.
[AllowedProcesses] Known business processes performing encryption or compression.
[TimeWindow] Correlation timeframe between script execution and file creation.
AN1214 Analytic 1214
Linux

Detects custom archive routines by correlating script execution (Python, Perl, Bash) with creation of high-entropy files in temporary or user directories. Flags processes performing unusual bitwise operations or writing files without standard compression headers.

auditd:SYSCALL execve: Execution of interpreters creating archive-like outputs without calling tar/gzip auditd:FILE create: Creation of files with anomalous headers and entropy levels in /tmp or user directories linux:osquery Detection of bitwise operations or custom encryption functions in memory traces
[ArchivePaths] Directories monitored for anomalous archive creation (e.g., /tmp, /home).
[EntropyThreshold] Entropy score to flag files lacking recognizable compression headers.
[ScriptAllowlist] Scripts/processes known to use custom compression methods.
AN1215 Analytic 1215
macOS

Detects custom archiving by monitoring execution of Swift/Objective-C apps or scripts producing high-entropy files with non-standard headers. Correlates unified logs of abnormal NSFileHandle/NSData operations, memory use of XOR/bitwise operations, and file creation events.

macos:unifiedlog Suspicious Swift/Objective-C or scripting processes writing archive-like outputs macos:unifiedlog Creation of files with anomalous headers and entropy values macos:unifiedlog Abnormal memory operations (XOR/bitwise loops) during archive generation
[UserContext] Flag if archiving occurs under privileged/system accounts.
[EntropyThreshold] Entropy score cutoff for identifying custom compressed or encrypted files.
[AllowedApps] Applications legitimately using custom archiving for business purposes.

Detected Techniques

1

Details

MITRE ID
DET0438
STIX ID
x-mitre-detection-strategy--edf894b7-052a-4baf-8984-f01ec773c80c
Analytics
3
Techniques Detected
1
By Tactic
Collection
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.