FORENSIA

ATT&CK · T1074

Data Staged

Tactics: collection

About

Adversaries may stage collected data in a central location or directory prior to Exfiltration. Data may be kept in separate files or combined into one file through techniques such as Archive Collected Data. Interactive command shells may be used, and common functionality within cmd and bash may be used to copy data into a staging location. In cloud environments, adversaries may stage data within a particular instance or virtual machine before exfiltration. An adversary may Create Cloud Instance and stage data in that instance. Adversaries may choose to stage data from a victim network in a centralized location prior to Exfiltration to minimize the number of connections made to their C2 server and better evade detection.

Platforms: ESXi, IaaS, Linux, macOS, WindowsMITRE ATT&CK ↗

Used by actors

5 known groups

Software

4 malware/tools implement this

KobalosSharkKevinQUIETCANARY

Corpus indicators tagged with this technique

24 indicators in the corpus carry T1074.

IndicatorTypeFamilySevSrc
41.128.0.142ipphishing701
buenne.dedomainphishing651
enerdizerandtron.dedomainphishing651
ihrsupportcenter.dedomainphishing651
rundwasser.dedomainphishing651
sonnenbrillenspot.dedomainphishing651
dwbud.vilaribit.comdomainphishing651
abal.mydomainphishing651
starwellmedia.comdomainphishing651
aabiz.dedomainphishing651
aspireglobal.ltddomainphishing651
dufllot.sbsdomainphishing651
espaciocf.dedomainphishing651
ilersls.orgdomainphishing651
aaalen.dedomainphishing651
smartcontrolengineer.comdomainphishing651
trisrnareprjdocz.comdomainphishing651
razen.onlinedomainphishing651
theoceanac.onlinedomainphishing651
crm-technik.dedomainphishing651
klenpare.comdomainphishing651
uvarnix.cfddomainphishing651
jumpast.esdomainphishing651
xavon.sbsdomainphishing651