1200KM / simulation
T1560.001 Archive via Utility — Attack Simulation
Adversaries may use utilities to compress and/or encrypt collected data prior to exfiltration. Many utilities include functionalities to compress, encrypt, or otherwise package data into a format that is easier/more secure to transport. Adversaries may abuse various utilities to compress or encrypt data before exfiltration. Some third party utilities may be preinstalled, such as tar on Linux and macOS or zip on Windows systems. On Windows,…
Technique description
Adversaries may use utilities to compress and/or encrypt collected data prior to exfiltration. Many utilities include functionalities to compress, encrypt, or otherwise package data into a format that is easier/more secure to transport. Adversaries may abuse various utilities to compress or encrypt data before exfiltration. Some third party utilities may be preinstalled, such as tar on Linux and macOS or zip on Windows systems. On Windows,…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Compress Data and lock with password for Exfiltration with winzip
Procedure 01df0353-d531-408d-a0c5-3161bf822134; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Data Encrypted with zip and gpg symmetric
Procedure 0286eb44-e7ce-41a0-b109-3da516e05a5f; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Compress Data for Exfiltration With Rar
Procedure 02ea31cb-3b4c-4a2d-9bf1-e4e70ebcf5d0; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Copy and Compress AppData Folder
Procedure 05e8942e-f04f-460a-b560-f7781257feec; elevation required; cleanup not declared. Not executed or individually validated.
- Data Compressed - macOS - ditto Archive of a Sensitive Directory
Procedure 2794f321-55c4-4484-9eef-0557996f715a; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Compress a File for Exfiltration using Makecab
Procedure 2a7bc405-9555-4f49-ace2-b2ae2941d629; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- ESXi - Remove Syslog remote IP
Procedure 36c62584-d360-41d6-886f-d194654be7c2; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Data Compressed - nix - tar Folder or File
Procedure 7af2b51e-ad1c-498c-aca8-d3290c19535a; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Compress Data and lock with password for Exfiltration with winrar
Procedure 8dd61a55-44c6-43cc-af0c-8bdda276860c; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Encrypts collected data with AES-256 and Base64
Procedure a743e3a6-e8b2-4a30-abe7-ca85d201b5d3; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Data Compressed - nix - zip
Procedure c51cec55-28dd-4ad2-9461-1eacbc82c3a0; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Data Compressed - nix - gzip Single File
Procedure cde3c2af-3485-49eb-9c1f-0ed60e9cc0af; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Compress Data and lock with password for Exfiltration with 7zip
Procedure d1334303-59cb-4a03-8313-b3e24d02c198; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- Ke3chang · G0004
- APT1 · G0006
- APT28 · G0007
- Turla · G0010
- APT3 · G0022
- Lotus Blossom · G0030
- menuPass · G0045
- CopyKittens · G0052
- Sowbug · G0054
- Magic Hound · G0059
- BRONZE BUTLER · G0060
- FIN8 · G0061
- APT33 · G0064
- MuddyWater · G0069
- Gallmaker · G0084
- APT39 · G0087
- GALLIUM · G0093
- Kimsuky · G0094
- APT41 · G0096
- Wizard Spider · G0102
- Chimera · G0114
- Fox Kitten · G0117
- HAFNIUM · G0125
- Mustang Panda · G0129
- Aquatic Panda · G0143
- Earth Lusca · G1006
- FIN13 · G1016
- Volt Typhoon · G1017
- ToddyCat · G1022
- APT5 · G1023
- Akira · G1024
- Agrius · G1030
- INC Ransom · G1032
- RedCurl · G1039
- Play · G1040
- Sea Turtle · G1041
- UNC3886 · G1048
- MirrorFace · G1054
- VOID MANTICORE · G1055
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.