FORENSIA

ATT&CK · T1074.001 · sub-technique

Local Data Staging

Tactics: collection

About

Adversaries may stage collected data in a central location or directory on the local system prior to Exfiltration. Data may be kept in separate files or combined into one file through techniques such as Archive Collected Data. Interactive command shells may be used, and common functionality within cmd and bash may be used to copy data into a staging location. Adversaries may also stage collected data in various available formats/locations of a system, including local storage databases/repositories or the Windows Registry.

Platforms: ESXi, Linux, macOS, WindowsParent: T1074 Data StagedMITRE ATT&CK ↗

Used by actors

28 known groups

Software

94 malware/tools implement this

PoisonIvyPlugXDyreSPACESHIPFLASHFLOODDuquADVSTORESHELLDustySkyEliseMis-TypeRoverTrojan.KaraganyPrikormkaBADNEWSUSBStealerPteranodonMoonWindRawPOSHelminthPUNCHBUGGYPUNCHTRACKNETWIRENavRATGold DragonZebrocyInvisiMoleCatchamasOopsIEKazuarCalistoCarbonBadPatchOctopusExaramel for WindowsNOKKIAstarothUrsnifLightNeuronMacheteAttorMESSAGETAPRamsayFrameworkPOSKGH_SPYCrutchDtrackECCENTRICBANDWAGONSombRATAppleSeedRainyDayObliqueRATTurianQakBotBoxCaonMarkiRATChrommmeDarkWatchmanPowerLessMilanMacMaAuTo StealerSTARWHALESUGARDUMPccf32FunnyDreammetaMainMafaldaKOPILUWAKNightClubLoFiSeSLOWPULSEPACEMAKERSLIGHTPULSESocGholishLunarMailCHIMNEYSWEEPCuckoo StealerVersaMemSampleCheck5000OilBoosterTroll StealerSagerunexLumma StealerRIFLESPINEPAKLOGCorKLOGInvisibleFerretBeaverTailGlassWormDRYHOOKLODEINFOMirrorStealerLAMEHUGLP-Notes

Corpus indicators tagged with this technique

131 indicators in the corpus carry T1074.001.