MITRE ATT&CK technique
Data Staged detection rulesT1074
Data Staged (T1074) is a MITRE ATT&CK technique in the Collection tactic. This page lists the 6 community-maintained Sigma detection rules in the library mapped to T1074 and its sub-techniques. Each rule includes its detection logic, log source, false positives and original YAML. These rules mainly target windows, gcp, cisco.
Tactic
Folder Compress To Potentially Suspicious Output Via Compress-Archive Cmdlet
mediumDetects PowerShell scripts that make use of the "Compress-Archive" Cmdlet in order to compress folders and files where the output is stored in a potentially suspicious location that is used often by malware for exfiltration. An adversary might compress data (e.g., sensitive documents) that is collected prior to exfiltration in order to make it portable and minimize the amount of data sent over the network.
windows · process_creation
Google Full Network Traffic Packet Capture
mediumIdentifies potential full network packet capture in gcp. This feature can potentially be abused to read sensitive data from unencrypted internal traffic.
gcp
Zip A Folder With PowerShell For Staging In Temp - PowerShell Module
mediumDetects PowerShell scripts that make use of the "Compress-Archive" Cmdlet in order to compress folders and files where the output is stored in a potentially suspicious location that is used often by malware for exfiltration. An adversary might compress data (e.g., sensitive documents) that is collected prior to exfiltration in order to make it portable and minimize the amount of data sent over the network.
windows · ps_module
Zip A Folder With PowerShell For Staging In Temp - PowerShell
mediumDetects PowerShell scripts that make use of the "Compress-Archive" Cmdlet in order to compress folders and files where the output is stored in a potentially suspicious location that is used often by malware for exfiltration. An adversary might compress data (e.g., sensitive documents) that is collected prior to exfiltration in order to make it portable and minimize the amount of data sent over the network.
windows
Zip A Folder With PowerShell For Staging In Temp - PowerShell Script
mediumDetects PowerShell scripts that make use of the "Compress-Archive" Cmdlet in order to compress folders and files where the output is stored in a potentially suspicious location that is used often by malware for exfiltration. An adversary might compress data (e.g., sensitive documents) that is collected prior to exfiltration in order to make it portable and minimize the amount of data sent over the network.
windows · ps_script
Cisco Stage Data
lowVarious protocols maybe used to put data on the device for exfil or infil
cisco