Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0526 — Detect Archiving and Encryption of Collected Data (T1560)
DET0526

Detect Archiving and Encryption of Collected Data (T1560)

3 analytic(s) · 1 technique(s) detected

Analytics

3
AN1458 Analytic 1458
Windows

Detects adversarial archiving of files prior to exfiltration by correlating execution of compression/encryption utilities (e.g., makecab.exe, rar.exe, 7z.exe, powershell Compress-Archive) with subsequent creation of large compressed or encrypted files. Identifies abnormal process lineage involving crypt32.dll usage, command-line arguments invoking compression switches, and file write operations to temporary or staging directories.

WinEventLog:Security EventCode=4688 WinEventLog:Sysmon EventCode=11 WinEventLog:Sysmon EventCode=7
[ArchiveExtensions] List of file extensions treated as suspicious when created outside of expected paths.
[ProcessAllowlist] Known business processes permitted to use compression/encryption utilities.
[FileSizeThresholdMB] Minimum file size for flagging archive creation to reduce noise from benign small compressions.
AN1459 Analytic 1459
Linux

Detects adversarial archiving activity through invocation of utilities like tar, gzip, bzip2, or openssl used in non-administrative or unusual contexts. Correlates command execution patterns with file creation of compressed/encrypted outputs in staging directories (e.g., /tmp, /var/tmp).

auditd:SYSCALL execve: Execution of tar, gzip, bzip2, or openssl with output redirection auditd:FILE create: Creation of files ending in .tar, .gz, .bz2, .zip in /tmp or /var/tmp
[ArchiveCommands] List of archiving/encryption utilities considered sensitive in the monitored environment.
[SuspiciousDirectories] Paths where archive creation is suspicious (e.g., /tmp, user home directories).
[TimeWindow] Temporal window to correlate command execution with file creation events.
AN1460 Analytic 1460
macOS

Detects use of macOS-native archiving or encryption tools (zip, ditto, hdiutil) for staging collected data. Identifies unexpected invocation of archive utilities by Office apps, browsers, or background daemons. Correlates file creation of .zip/.dmg containers with process lineage anomalies.

macos:unifiedlog Execution of zip, ditto, hdiutil, or openssl by non-terminal parent processes macos:unifiedlog Creation of .zip or .dmg files in user-accessible or temporary directories
[AllowedArchiveUtilities] Business-approved applications (e.g., Time Machine, backup agents) that generate archives.
[UserContext] Threshold for flagging archive creation under privileged or service accounts.
[PayloadEntropyThreshold] Entropy threshold for detecting encrypted archives versus standard compressed files.

Detected Techniques

1

Details

MITRE ID
DET0526
STIX ID
x-mitre-detection-strategy--043bc738-1f07-4d28-9f5c-1b1f81525e7c
Analytics
3
Techniques Detected
1
By Tactic
Collection
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.