1200KM / simulation
T1074.001 Local Data Staging — Attack Simulation
Adversaries may stage collected data in a central location or directory on the local system prior to Exfiltration. Data may be kept in separate files or combined into one file through techniques such as Archive Collected Data. Interactive command shells may be used, and common functionality within cmd and bash may be used to copy data into a staging location. Adversaries may also stage collected data in various available formats/locations of a…
Technique description
Adversaries may stage collected data in a central location or directory on the local system prior to Exfiltration. Data may be kept in separate files or combined into one file through techniques such as Archive Collected Data. Interactive command shells may be used, and common functionality within cmd and bash may be used to copy data into a staging location. Adversaries may also stage collected data in various available formats/locations of a…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Stage data from Discovery.bat
Procedure 107706a5-6f9f-451a-adae-bab8c667829f; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Stage data from Discovery.sh
Procedure 39ce0303-ae16-4b9e-bb5b-4f53e8262066; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Zip a Folder with PowerShell for Staging in Temp
Procedure a57fbe4b-3440-452a-88a7-943531ac872a; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
No reviewed association in this snapshot.
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- APT28 · G0007
- APT3 · G0022
- Threat Group-3390 · G0027
- Lotus Blossom · G0030
- Lazarus Group · G0032
- Dragonfly · G0035
- Patchwork · G0040
- menuPass · G0045
- FIN5 · G0053
- Leviathan · G0065
- MuddyWater · G0069
- APT39 · G0087
- WIRTE · G0090
- GALLIUM · G0093
- Kimsuky · G0094
- Wizard Spider · G0102
- Chimera · G0114
- Indrik Spider · G0119
- Sidewinder · G0121
- Mustang Panda · G0129
- BackdoorDiplomacy · G0135
- TeamTNT · G0139
- FIN13 · G1016
- Volt Typhoon · G1017
- APT5 · G1023
- Agrius · G1030
- Storm-1811 · G1046
- UNC3886 · G1048
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.