Umbra Wiki technique technique/T1560
Back to wiki

T1560 — Archive Collected Data

provenance: imported · ATT&CK: T1560

T1560: Archive Collected Data

MITRE ATT&CK® Enterprise technique

Tactics Collection
Platforms Linux, macOS, Windows
Permissions required
Version 1.0

Description

An adversary may compress and/or encrypt data that is collected prior to exfiltration. Compressing the data can help to obfuscate the collected data and minimize the amount of data sent over the network.(Citation: DOJ GRU Indictment Jul 2018) Encryption can be used to hide information that is being exfiltrated from detection or make exfiltration less conspicuous upon inspection by a defender.

Both compression and encryption are done prior to exfiltration, and can be performed using a utility, 3rd party library, or custom method.

Detection

(no detection guidance published)

Data sources

  • (none listed)

References

  • ATT&CK page: https://attack.mitre.org/techniques/T1560
  • ATT&CK Enterprise matrix: https://attack.mitre.org/matrices/enterprise/