Esc
Archive via Utility - T1560.001
(ATT&CK® Technique)
Definition
Adversaries may use utilities to compress and/or encrypt collected data prior to exfiltration. Many utilities include functionalities to compress, encrypt, or otherwise package data into a format that is easier/more secure to transport.
D3FEND Inferred Relationships
Browse the D3FEND knowledge graph by clicking on the nodes below.
graph LR;
T1560001["Archive via Utility"] --> |creates| ArchiveFile["Archive File"]; class T1560001 OffensiveTechniqueNode;
class ArchiveFile ArtifactNode; click ArchiveFile href "../../../dao/artifact/d3f:ArchiveFile";
click T1560001 href "../../../offensive-technique/attack/T1560.001/"; click ArchiveFile href "../../../dao/artifact/d3f:ArchiveFile"; FileIntegrityMonitoring["File Integrity Monitoring"] -->
| analyzes | ArchiveFile["Archive File"];
FileIntegrityMonitoring["File Integrity Monitoring"] -.->
| may-detect | T1560001["Archive via Utility"] ;
class FileIntegrityMonitoring DefensiveTechniqueNode;
class ArchiveFile ArtifactNode;
click FileIntegrityMonitoring href "../../../technique/d3f:FileIntegrityMonitoring"; FileEviction["File Eviction"] -->
| deletes | ArchiveFile["Archive File"];
FileEviction["File Eviction"] -.->
| may-evict | T1560001["Archive via Utility"] ;
class FileEviction DefensiveTechniqueNode;
class ArchiveFile ArtifactNode;
click FileEviction href "../../../technique/d3f:FileEviction"; DecoyFile["Decoy File"] -->
| spoofs | ArchiveFile["Archive File"];
DecoyFile["Decoy File"] -.->
| may-deceive | T1560001["Archive via Utility"] ;
class DecoyFile DefensiveTechniqueNode;
class ArchiveFile ArtifactNode;
click DecoyFile href "../../../technique/d3f:DecoyFile"; ContentModification["Content Modification"] -->
| modifies | ArchiveFile["Archive File"];
ContentModification["Content Modification"] -.->
| may-isolate | T1560001["Archive via Utility"] ;
class ContentModification DefensiveTechniqueNode;
class ArchiveFile ArtifactNode;
click ContentModification href "../../../technique/d3f:ContentModification"; ContentQuarantine["Content Quarantine"] -->
| quarantines | ArchiveFile["Archive File"];
ContentQuarantine["Content Quarantine"] -.->
| may-isolate | T1560001["Archive via Utility"] ;
class ContentQuarantine DefensiveTechniqueNode;
class ArchiveFile ArtifactNode;
click ContentQuarantine href "../../../technique/d3f:ContentQuarantine"; LocalFilePermissions["Local File Permissions"] -->
| restricts | ArchiveFile["Archive File"];
LocalFilePermissions["Local File Permissions"] -.->
| may-isolate | T1560001["Archive via Utility"] ;
class LocalFilePermissions DefensiveTechniqueNode;
class ArchiveFile ArtifactNode;
click LocalFilePermissions href "../../../technique/d3f:LocalFilePermissions"; FileEncryption["File Encryption"] -->
| encrypts | ArchiveFile["Archive File"];
FileEncryption["File Encryption"] -.->
| may-harden | T1560001["Archive via Utility"] ;
class FileEncryption DefensiveTechniqueNode;
class ArchiveFile ArtifactNode;
click FileEncryption href "../../../technique/d3f:FileEncryption"; RestoreFile["Restore File"] -->
| restores | ArchiveFile["Archive File"];
RestoreFile["Restore File"] -.->
| may-restore | T1560001["Archive via Utility"] ;
class RestoreFile DefensiveTechniqueNode;
class ArchiveFile ArtifactNode;
click RestoreFile href "../../../technique/d3f:RestoreFile"; FileAnalysis["File Analysis"] -->
| analyzes | ArchiveFile["Archive File"];
FileAnalysis["File Analysis"] -.->
| may-detect | T1560001["Archive via Utility"] ;
class FileAnalysis DefensiveTechniqueNode;
class ArchiveFile ArtifactNode;
click FileAnalysis href "../../../technique/d3f:FileAnalysis"; ContentFiltering["Content Filtering"] -->
| filters | ArchiveFile["Archive File"];
ContentFiltering["Content Filtering"] -.->
| may-isolate | T1560001["Archive via Utility"] ;
class ContentFiltering DefensiveTechniqueNode;
class ArchiveFile ArtifactNode;
click ContentFiltering href "../../../technique/d3f:ContentFiltering"; RemoteFileAccessMediation["Remote File Access Mediation"] -->
| isolates | ArchiveFile["Archive File"];
RemoteFileAccessMediation["Remote File Access Mediation"] -.->
| may-isolate | T1560001["Archive via Utility"] ;
class RemoteFileAccessMediation DefensiveTechniqueNode;
class ArchiveFile ArtifactNode;
click RemoteFileAccessMediation href "../../../technique/d3f:RemoteFileAccessMediation";