1200KM / detection
T1074.001 Local Data Staging — Detection Rules
Detection workspace for T1074.001 Local Data Staging: 4 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Zip A Folder With PowerShell For Staging In Temp - PowerShell · test · medium · {"product":"windows","service":"powershell-classic"}
- Zip A Folder With PowerShell For Staging In Temp - PowerShell Module · test · medium · {"product":"windows","category":"ps_module","definition":"0ad03ef1-f21b-4a79-8ce8-e6900c54b65b"}
- Zip A Folder With PowerShell For Staging In Temp - PowerShell Script · test · medium · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- Folder Compress To Potentially Suspicious Output Via Compress-Archive Cmdlet · test · medium · {"product":"windows","category":"process_creation"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0261 Detection of Local Data Staging Prior to Exfiltration
AN0724 Analytic 0724
Detects file reads across locations followed by writes to temp or staging directories, often compressed or encrypted, indicating local staging behavior.
AN0725 Analytic 0725
Detects aggregation of files from different directories into /tmp, /mnt, or user-specified directories with archiving tools like tar or gzip.
AN0726 Analytic 0726
Detects staged data aggregated in /Users/Shared, /private/tmp with compression tools like ditto or zip, initiated via Terminal or AppleScript.
AN0727 Analytic 0727
Detects local staging behavior via snapshot creation or files written into VMFS partitions by scripts or unauthorized shell access.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
T1074.001 simulation workspace
- Command Execution · DC0064
- File Access · DC0055
- File Creation · DC0039
- Process Creation · DC0032
- Snapshot Creation · DC0057
No reviewed association in this snapshot.
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- APT28 · G0007
- APT3 · G0022
- Threat Group-3390 · G0027
- Lotus Blossom · G0030
- Lazarus Group · G0032
- Dragonfly · G0035
- Patchwork · G0040
- menuPass · G0045
- FIN5 · G0053
- Leviathan · G0065
- MuddyWater · G0069
- APT39 · G0087
- WIRTE · G0090
- GALLIUM · G0093
- Kimsuky · G0094
- Wizard Spider · G0102
- Chimera · G0114
- Indrik Spider · G0119
- Sidewinder · G0121
- Mustang Panda · G0129
- BackdoorDiplomacy · G0135
- TeamTNT · G0139
- FIN13 · G1016
- Volt Typhoon · G1017
- APT5 · G1023
- Agrius · G1030
- Storm-1811 · G1046
- UNC3886 · G1048
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.