1200kmSECURITY RESEARCH
Loading interactive filters…

1200KM / detection

T1074 Data Staged — Detection Rules

Detection workspace for T1074 Data Staged: 2 Sigma sources, 1 Atlas concepts and 1 anomaly models. No live detection validation.

Source-backed rule directory

Atlas deterministic concepts

T1074 Data Staged

MATCH(archive_or_compression_process) AND output_path IN staging_paths -> ALERT; COUNT(files_created_in_staging_path, 10m) >= threshold -> ALERT

Anomaly models

ATT&CK analytic guidance

DET0014 Detection of Data Staging Prior to Exfiltration

AN0040 Analytic 0040

Detects staging of sensitive files into temporary or public directories, compression with 7zip/WinRAR, or batch copy prior to exfiltration.

AN0041 Analytic 0041

Detects script or user activity copying files to a central temp or /mnt directory followed by archive/compression utilities.

AN0042 Analytic 0042

Detects files collected into user temp or shared directories followed by compression with ditto, zip, or custom scripts.

AN0043 Analytic 0043

Detects virtual disk expansion or file copy operations to cloud buckets or mounted volumes from isolated instances.

AN0044 Analytic 0044

Detects snapshots or data stored in VMFS volumes from root CLI or remote agents.

Connected ecosystem references

Linked tags

Simulation, tools and telemetry

T1074 simulation workspace

No reviewed association in this snapshot.

Threat actor context

These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.

Existing anomaly research

Original publication snapshot · Anomaly Detection Atlas

Connected anomaly research

Curated research views reached through an exact source technique, a catalog model, or a reviewed collection reference. These are navigation associations, not claims of detector effectiveness or sensor equivalence.

Telemetry contracts · Maintained query examples · Validation and blind spots

Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.