{"id":"T1560.001","name":"Archive via Utility","url":"https://attack.mitre.org/techniques/T1560/001","tactics":["collection"],"platforms":["Linux","macOS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0298","stix_id":"x-mitre-detection-strategy--e8528ab8-3467-423b-92b6-115f8ecc266d","name":"Detect Archiving via Utility (T1560.001)","url":"https://attack.mitre.org/detectionstrategies/DET0298","analytics":[{"id":"AN0831","stix_id":"x-mitre-analytic--ebfa3aa8-dc7c-4d56-868e-169c873b5e78","name":"Analytic 0831","description":"Detects adversarial archiving using built-in or third-party utilities (makecab, diantz, xcopy, certutil, 7z, WinRAR, WinZip). Correlates suspicious process creation events with command-line arguments for compression/encoding, followed by creation of archive files (.cab, .zip, .7z, .rar). Identifies anomalous loading of crypt32.dll for encryption operations or execution of diantz.exe to compress remotely staged files.","url":"https://attack.mitre.org/detectionstrategies/DET0298#AN0831","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4688","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Sysmon","channel":"EventCode=11","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=7","data_component":"DC0016","data_component_name":"Module Load","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"SuspiciousExtensions","description":"List of archive extensions considered high risk (.cab, .zip, .7z, .rar)."},{"field":"ProcessAllowlist","description":"Known business utilities allowed to create archives without alerting."},{"field":"FileSizeThresholdMB","description":"Minimum archive size threshold to filter out benign small compressions."}],"live":true,"detection_strategies":["DET0298"],"techniques":["T1560.001"]},{"id":"AN0832","stix_id":"x-mitre-analytic--89cfa3ac-22c9-462f-a6a5-b142124e22a5","name":"Analytic 0832","description":"Detects execution of archiving utilities (tar, gzip, bzip2, xz, zip, openssl) followed by suspicious archive file creation. Correlates archive creation in temporary or staging directories with execution of commands involving compression or encryption options.","url":"https://attack.mitre.org/detectionstrategies/DET0298#AN0832","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve: Execution of tar, gzip, bzip2, xz, zip, or openssl with compression/encryption arguments","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"auditd-syscall"},{"name":"auditd:FILE","channel":"create: Creation of archive files in /tmp, /var/tmp, or user home directories","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"auditd-file"}],"mutable_elements":[{"field":"ArchiveCommands","description":"List of archiving utilities considered suspicious."},{"field":"MonitoredDirectories","description":"Paths where archive creation is flagged as unusual (e.g., /tmp, /var/tmp)."},{"field":"TimeWindow","description":"Correlation window for linking utility execution with archive creation."}],"live":true,"detection_strategies":["DET0298"],"techniques":["T1560.001"]},{"id":"AN0833","stix_id":"x-mitre-analytic--18cf5cf7-f46b-4258-a0aa-503881c9c88e","name":"Analytic 0833","description":"Detects invocation of macOS-native archiving utilities (zip, ditto, hdiutil) or openssl used for encryption. Correlates execution with archive or encrypted file creation (.zip, .dmg, .tar.gz) in user or temporary directories. Identifies anomalous use of archiving commands by Office applications or daemons.","url":"https://attack.mitre.org/detectionstrategies/DET0298#AN0833","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"Execution of zip, ditto, hdiutil, or openssl by processes not normally associated with archiving","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"Creation of .zip, .dmg, .tar.gz files in /Users, /tmp, or application directories","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"AllowedArchivers","description":"Business-approved applications permitted to create archives (e.g., backup agents)."},{"field":"UserContext","description":"Flag archiving under privileged or service accounts as higher risk."},{"field":"PayloadEntropyThreshold","description":"Entropy threshold for detecting encrypted archives versus normal compression."}],"live":true,"detection_strategies":["DET0298"],"techniques":["T1560.001"]}],"live":true,"version":"1.0","techniques":["T1560.001"]}],"sigma_rules":[{"id":"03e2746e-2b31-42f1-ab7a-eb39365b2422","title":"APT31 Judgement Panda Activity","author":"Florian Roth (Nextron Systems)","status":"test","level":"critical","date":"2019-02-21","modified":"2023-03-10","description":"Detects APT31 Judgement Panda activity as described in the Crowdstrike 2019 Global Threat Report","references":["https://www.documentcloud.org/documents/5743766-Global-Threat-Report-2019.html"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.collection","attack.lateral-movement","attack.credential-access","attack.g0128","attack.t1003.001","attack.t1560.001","detection.emerging-threats"],"path":"rules-emerging-threats/2019/TA/APT31/proc_creation_win_apt_apt31_judgement_panda.yml","techniques":["T1003.001","T1560.001"],"cves":[]},{"id":"1ac14d38-3dfc-4635-92c7-e3fd1c5f5bfc","title":"Winrar Compressing Dump Files","author":"Florian Roth (Nextron Systems)","status":"test","level":"medium","date":"2022-01-04","modified":"2023-09-12","description":"Detects execution of WinRAR in order to compress a file with a \".dmp\"/\".dump\" extension, which could be a step in a process of dump file exfiltration.","references":["https://www.crowdstrike.com/blog/overwatch-exposes-aquatic-panda-in-possession-of-log-4-shell-exploit-tools/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.collection","attack.t1560.001"],"path":"rules/windows/process_creation/proc_creation_win_winrar_exfil_dmp_files.yml","techniques":["T1560.001"],"cves":[]},{"id":"27a72a60-7e5e-47b1-9d17-909c9abafdcd","title":"Potentially Suspicious Compression Tool Parameters","author":"Florian Roth (Nextron Systems), Samir Bousseaden","status":"test","level":"medium","date":"2019-10-15","modified":"2023-08-29","description":"Detects potentially suspicious command line arguments of common data compression tools","references":["https://twitter.com/SBousseaden/status/1184067445612535811"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.collection","attack.t1560.001","detection.threat-hunting"],"path":"rules-threat-hunting/windows/process_creation/proc_creation_win_susp_compression_params.yml","techniques":["T1560.001"],"cves":[]},{"id":"36603778-030c-43c4-8cbb-cd3c1d1a80c7","title":"LiteLLM / TeamPCP Supply Chain Attack Indicators","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"high","date":"2026-03-30","modified":null,"description":"Detects process executions related to the backdoored versions of LiteLLM (v1.82.7 or v1.82.8).\nIn March 2026, a supply chain attack was discovered involving the popular open-source LLM framework LiteLLM by Threat Actor TeamPCP.\nThe malicious package harvests every credential on the system, encrypts and exfiltrates them, and installs a persistent C2 backdoor.\n","references":["https://novasky.io/hunts/hunting-litellm-supply-chain","https://www.virustotal.com/gui/file/71e35aef03099cd1f2d6446734273025a163597de93912df321ef118bf135238/","https://huskyhacks.io/posts/litellm-cred-stealer/","https://www.wiz.io/blog/threes-a-crowd-teampcp-trojanizes-litellm-in-continuation-of-campaign"],"logsource":{"product":"linux","category":"process_creation"},"tags":["attack.initial-access","attack.t1195.002","attack.collection","attack.t1560.001","attack.persistence","attack.privilege-escalation","attack.t1543.002","detection.emerging-threats"],"path":"rules-emerging-threats/2026/TA/TeamPCP/proc_creation_lnx_teampcp_litellm_supply_chain_attack_indicators.yml","techniques":["T1195.002","T1560.001","T1543.002"],"cves":[]},{"id":"418a3163-3247-4b7b-9933-dcfcb7c52ea9","title":"Compressed File Creation Via Tar.EXE","author":"Nasreddine Bencherchali (Nextron Systems), AdmU3","status":"test","level":"low","date":"2023-12-19","modified":null,"description":"Detects execution of \"tar.exe\" in order to create a compressed file.\nAdversaries may abuse various utilities to compress or encrypt data before exfiltration.\n","references":["https://unit42.paloaltonetworks.com/chromeloader-malware/","https://lolbas-project.github.io/lolbas/Binaries/Tar/","https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/cicada-apt10-japan-espionage"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.collection","attack.exfiltration","attack.t1560","attack.t1560.001"],"path":"rules/windows/process_creation/proc_creation_win_tar_compression.yml","techniques":["T1560","T1560.001"],"cves":[]},{"id":"4ede543c-e098-43d9-a28f-dd784a13132f","title":"WinRAR Execution in Non-Standard Folder","author":"Florian Roth (Nextron Systems), Tigzy","status":"test","level":"medium","date":"2021-11-17","modified":"2025-07-16","description":"Detects a suspicious WinRAR execution in a folder which is not the default installation folder","references":["https://twitter.com/cyb3rops/status/1460978167628406785"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.collection","attack.t1560.001"],"path":"rules/windows/process_creation/proc_creation_win_winrar_uncommon_folder_execution.yml","techniques":["T1560.001"],"cves":[]},{"id":"5b768e71-86f2-4879-b448-81061cbae951","title":"Suspicious Manipulation Of Default Accounts Via Net.EXE","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2022-09-01","modified":"2023-02-21","description":"Detects suspicious manipulations of default accounts such as 'administrator' and 'guest'. For example 'enable' or 'disable' accounts or change the password...etc","references":["https://www.trellix.com/en-sg/about/newsroom/stories/threat-labs/lockergoga-ransomware-family-used-in-targeted-attacks.html","https://redacted.com/blog/bianlian-ransomware-gang-gives-it-a-go/","https://www.microsoft.com/security/blog/2022/09/07/profiling-dev-0270-phosphorus-ransomware-operations/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.collection","attack.t1560.001"],"path":"rules/windows/process_creation/proc_creation_win_net_user_default_accounts_manipulation.yml","techniques":["T1560.001"],"cves":[]},{"id":"5e51acb2-bcbe-435b-99c6-0e3cd5e2aa59","title":"Cisco Stage Data","author":"Austin Clark","status":"test","level":"low","date":"2019-08-12","modified":"2023-01-04","description":"Various protocols maybe used to put data on the device for exfil or infil","references":[],"logsource":{"product":"cisco","service":"aaa"},"tags":["attack.collection","attack.lateral-movement","attack.command-and-control","attack.exfiltration","attack.t1074","attack.t1105","attack.t1560.001"],"path":"rules/network/cisco/aaa/cisco_cli_moving_data.yml","techniques":["T1074","T1105","T1560.001"],"cves":[]},{"id":"6f3e2987-db24-4c78-a860-b4f4095a7095","title":"Files Added To An Archive Using Rar.EXE","author":"Timur Zinniatullin, E.M. Anhaus, oscd.community","status":"test","level":"low","date":"2019-10-21","modified":"2023-02-05","description":"Detects usage of \"rar\" to add files to an archive for potential compression. An adversary may compress data (e.g. sensitive documents) that is collected prior to exfiltration in order to make it portable and minimize the amount of data sent over the network.","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1560.001/T1560.001.md","https://eqllib.readthedocs.io/en/latest/analytics/1ec33c93-3d0b-4a28-8014-dbdaae5c60ae.html"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.collection","attack.t1560.001"],"path":"rules/windows/process_creation/proc_creation_win_rar_compress_data.yml","techniques":["T1560.001"],"cves":[]},{"id":"9fbf5927-5261-4284-a71d-f681029ea574","title":"Compress Data and Lock With Password for Exfiltration With 7-ZIP","author":"frack113","status":"test","level":"medium","date":"2021-07-27","modified":"2026-06-05","description":"An adversary may compress or encrypt data that is collected prior to exfiltration using 3rd party utilities","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1560.001/T1560.001.md"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.collection","attack.t1560.001"],"path":"rules/windows/process_creation/proc_creation_win_7zip_password_compression.yml","techniques":["T1560.001"],"cves":[]},{"id":"a3b5e3e9-1b49-4119-8b8e-0344a01f21ee","title":"Data Compressed","author":"Timur Zinniatullin, oscd.community","status":"test","level":"low","date":"2019-10-21","modified":"2023-07-28","description":"An adversary may compress data (e.g., sensitive documents) that is collected prior to exfiltration in order to make it portable and minimize the amount of data sent over the network.","references":["https://github.com/redcanaryco/atomic-red-team/blob/a78b9ed805ab9ea2e422e1aa7741e9407d82d7b1/atomics/T1560.001/T1560.001.md"],"logsource":{"product":"linux","service":"auditd"},"tags":["attack.exfiltration","attack.collection","attack.t1560.001"],"path":"rules/linux/auditd/execve/lnx_auditd_data_compressed.yml","techniques":["T1560.001"],"cves":[]},{"id":"b717b8fd-6467-4d7d-b3d3-27f9a463af77","title":"Password Protected Compressed File Extraction Via 7Zip","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"low","date":"2023-03-10","modified":"2026-06-05","description":"Detects usage of 7zip utilities (7z.exe, 7za.exe and 7zr.exe) to extract password protected zip files.","references":["https://blog.cyble.com/2022/06/07/bumblebee-loader-on-the-rise/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.collection","attack.t1560.001","detection.threat-hunting"],"path":"rules-threat-hunting/windows/process_creation/proc_creation_win_7zip_password_extraction.yml","techniques":["T1560.001"],"cves":[]},{"id":"bf241472-f014-4f01-a869-96f99330ca8c","title":"Disk Image Mounting Via Hdiutil - MacOS","author":"Omar Khaled (@beacon_exe)","status":"test","level":"medium","date":"2024-08-10","modified":null,"description":"Detects the execution of the hdiutil utility in order to mount disk images.","references":["https://www.loobins.io/binaries/hdiutil/","https://www.sentinelone.com/blog/from-the-front-linesunsigned-macos-orat-malware-gambles-for-the-win/","https://ss64.com/mac/hdiutil.html"],"logsource":{"product":"macos","category":"process_creation"},"tags":["attack.initial-access","attack.collection","attack.t1566.001","attack.t1560.001"],"path":"rules/macos/process_creation/proc_creation_macos_hdiutil_mount.yml","techniques":["T1566.001","T1560.001"],"cves":[]},{"id":"bf361876-6620-407a-812f-bfe11e51e924","title":"Compressed File Extraction Via Tar.EXE","author":"AdmU3","status":"test","level":"low","date":"2023-12-19","modified":null,"description":"Detects execution of \"tar.exe\" in order to extract compressed file.\nAdversaries may abuse various utilities in order to decompress data to avoid detection.\n","references":["https://unit42.paloaltonetworks.com/chromeloader-malware/","https://lolbas-project.github.io/lolbas/Binaries/Tar/","https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/cicada-apt10-japan-espionage"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.collection","attack.exfiltration","attack.t1560","attack.t1560.001"],"path":"rules/windows/process_creation/proc_creation_win_tar_extraction.yml","techniques":["T1560","T1560.001"],"cves":[]},{"id":"e2e80da2-8c66-4e00-ae3c-2eebd29f6b6d","title":"Compress Data and Lock With Password for Exfiltration With WINZIP","author":"frack113","status":"test","level":"medium","date":"2021-07-27","modified":"2022-12-25","description":"An adversary may compress or encrypt data that is collected prior to exfiltration using 3rd party utilities","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1560.001/T1560.001.md"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.collection","attack.t1560.001"],"path":"rules/windows/process_creation/proc_creation_win_winzip_password_compression.yml","techniques":["T1560.001"],"cves":[]},{"id":"ec570e53-4c76-45a9-804d-dc3f355ff7a7","title":"7Zip Compressing Dump Files","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2022-09-27","modified":"2026-06-05","description":"Detects execution of 7z in order to compress a file with a \".dmp\"/\".dump\" extension, which could be a step in a process of dump file exfiltration.","references":["https://thedfirreport.com/2022/09/26/bumblebee-round-two/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.collection","attack.t1560.001"],"path":"rules/windows/process_creation/proc_creation_win_7zip_exfil_dmp_files.yml","techniques":["T1560.001"],"cves":[]},{"id":"faa48cae-6b25-4f00-a094-08947fef582f","title":"Rar Usage with Password and Compression Level","author":"@ROxPinTeddy","status":"test","level":"high","date":"2020-05-12","modified":"2022-03-16","description":"Detects the use of rar.exe, on the command line, to create an archive with password protection or with a specific compression level. This is pretty indicative of malicious actions.","references":["https://labs.sentinelone.com/the-anatomy-of-an-apt-attack-and-cobaltstrike-beacons-encoded-configuration/","https://ss64.com/bash/rar.html","https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1560.001/T1560.001.md"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.collection","attack.t1560.001"],"path":"rules/windows/process_creation/proc_creation_win_rar_compression_with_password.yml","techniques":["T1560.001"],"cves":[]}],"kev_cves":[{"cveID":"CVE-2021-44077","state":"mapped","mapping_types":["secondary_impact"]},{"cveID":"CVE-2021-40539","state":"mapped","mapping_types":["secondary_impact"]}],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}