MITRE ATT&CK technique
Archive Collected Data detection rulesT1560
Archive Collected Data (T1560) is a MITRE ATT&CK technique in the Collection tactic. This page lists the 19 community-maintained Sigma detection rules in the library mapped to T1560 and its sub-techniques. Each rule includes its detection logic, log source, false positives and original YAML. These rules mainly target windows, linux, macos.
Tactic
APT31 Judgement Panda Activity
criticalDetects APT31 Judgement Panda activity as described in the Crowdstrike 2019 Global Threat Report
windows · process_creation
Conti NTDS Exfiltration Command
highDetects a command used by conti to exfiltrate NTDS
windows · process_creation
LiteLLM / TeamPCP Supply Chain Attack Indicators
highDetects process executions related to the backdoored versions of LiteLLM (v1.82.7 or v1.82.8). In March 2026, a supply chain attack was discovered involving the popular open-source LLM framework LiteLLM by Threat Actor TeamPCP. The malicious package harvests every credential on the system, encrypts and exfiltrates them, and installs a persistent C2 backdoor.
linux · process_creation
Rar Usage with Password and Compression Level
highDetects the use of rar.exe, on the command line, to create an archive with password protection or with a specific compression level. This is pretty indicative of malicious actions.
windows · process_creation
Suspicious Manipulation Of Default Accounts Via Net.EXE
highDetects suspicious manipulations of default accounts such as 'administrator' and 'guest'. For example 'enable' or 'disable' accounts or change the password...etc
windows · process_creation
7Zip Compressing Dump Files
mediumDetects execution of 7z in order to compress a file with a ".dmp"/".dump" extension, which could be a step in a process of dump file exfiltration.
windows · process_creation
Compress Data and Lock With Password for Exfiltration With 7-ZIP
mediumAn adversary may compress or encrypt data that is collected prior to exfiltration using 3rd party utilities
windows · process_creation
Compress Data and Lock With Password for Exfiltration With WINZIP
mediumAn adversary may compress or encrypt data that is collected prior to exfiltration using 3rd party utilities
windows · process_creation
Disk Image Mounting Via Hdiutil - MacOS
mediumDetects the execution of the hdiutil utility in order to mount disk images.
macos · process_creation
Potentially Suspicious Compression Tool Parameters
mediumDetects potentially suspicious command line arguments of common data compression tools
windows · process_creation
Winrar Compressing Dump Files
mediumDetects execution of WinRAR in order to compress a file with a ".dmp"/".dump" extension, which could be a step in a process of dump file exfiltration.
windows · process_creation
WinRAR Execution in Non-Standard Folder
mediumDetects a suspicious WinRAR execution in a folder which is not the default installation folder
windows · process_creation
Cisco Stage Data
lowVarious protocols maybe used to put data on the device for exfil or infil
cisco
Compress-Archive Cmdlet Execution
lowDetects PowerShell scripts that make use of the "Compress-Archive" cmdlet in order to compress folders and files. An adversary might compress data (e.g., sensitive documents) that is collected prior to exfiltration in order to make it portable and minimize the amount of data sent over the network.
windows · ps_script
Compressed File Creation Via Tar.EXE
lowDetects execution of "tar.exe" in order to create a compressed file. Adversaries may abuse various utilities to compress or encrypt data before exfiltration.
windows · process_creation
Compressed File Extraction Via Tar.EXE
lowDetects execution of "tar.exe" in order to extract compressed file. Adversaries may abuse various utilities in order to decompress data to avoid detection.
windows · process_creation
Data Compressed
lowAn adversary may compress data (e.g., sensitive documents) that is collected prior to exfiltration in order to make it portable and minimize the amount of data sent over the network.
linux
Files Added To An Archive Using Rar.EXE
lowDetects usage of "rar" to add files to an archive for potential compression. An adversary may compress data (e.g. sensitive documents) that is collected prior to exfiltration in order to make it portable and minimize the amount of data sent over the network.
windows · process_creation
Password Protected Compressed File Extraction Via 7Zip
lowDetects usage of 7zip utilities (7z.exe, 7za.exe and 7zr.exe) to extract password protected zip files.
windows · process_creation