Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/T1560
MITRE ATT&CK Technique

T1560: Archive Collected Data

ShareXLinkedInRedditHN

An adversary may compress and/or encrypt data that is collected prior to exfiltration. Compressing the data can help to obfuscate the collected data and minimize the amount of data sent over the network.(Citation: DOJ GRU Indictment Jul 2018) Encryption can be used to hide information that is being exfiltrated from detection or make exfiltration less conspicuous upon inspection by a defender. Both compression and encryption are done prior to exfiltration, and can be performed using a utility, 3rd party library, or custom method.

Tactics
Collection
Platforms
Linux, macOS, Windows

▪Sub-techniques (3)

T1560.001Archive via UtilityT1560.002Archive via LibraryT1560.003Archive via Custom Method

▪Mitigations (1)

M1047Audit

Auditing is the process of recording activity and systematically reviewing and analyzing the activity and system configurations. The primary purpose of auditing is to detect anomalies and identify potential threats or weaknesses in the environment. Proper auditing configurations can also help to meet compliance requirements. The process of auditing encompasses regular analysis of user behaviors and system logs in support of proactive security measures. Auditing is applicable to all systems used within an organization, from the front door of a building to accessing a file on a fileserver. It is considered more critical for regulated industries such as, healthcare, finance and government where compliance requirements demand stringent tracking of user and system activates.This mitigation can be implemented through the following measures: System Audit: - Use Case: Regularly assess system configurations to ensure compliance with organizational security policies. - Implementation: Use tools to scan for deviations from established benchmarks. Permission Audits: - Use Case: Review file and folder permissions to minimize the risk of unauthorized access or privilege escalation. - Implementation: Run access reviews to identify users or groups with excessive permissions. Software Audits: - Use Case: Identify outdated, unsupported, or insecure software that could serve as an attack vector. - Implementation: Use inventory and vulnerability scanning tools to detect outdated versions and recommend secure alternatives. Configuration Audits: - Use Case: Evaluate system and network configurations to ensure secure settings (e.g., disabled SMBv1, enabled MFA). - Implementation: Implement automated configuration scanning tools like SCAP (Security Content Automation Protocol) to identify non-compliant systems. Network Audits: - Use Case: Examine network traffic, firewall rules, and endpoint communications to identify unauthorized or insecure connections. - Implementation: Utilize tools such as Wireshark, or Zeek to monitor and log suspicious network behavior.

▪Used by groups (13)

G0001AxiomG0004Ke3changG0007APT28G0032Lazarus GroupG0035DragonflyG0037FIN6G0040PatchworkG0045menuPassG0050APT32G0065LeviathanG1003Ember BearG1014LuminousMothG1043BlackByte

▪Software using this technique (43)

S0010LuridmalwareS0045ADVSTORESHELLmalwareS0091EpicmalwareS0093Backdoor.OldreamalwareS0113PrikormkamalwareS0187DaserfmalwareS0198NETWIREmalwareS0249Gold DragonmalwareS0251ZebrocymalwareS0253RunningRATmalwareS0257VERMINmalwareS0267FELIXROOTmalwareS0279ProtonmalwareS0331Agent TeslamalwareS0343Exaramel for WindowsmalwareS0356KONNImalwareS0363EmpiretoolS0375RemeximalwareS0395LightNeuronmalwareS0409MachetemalwareS0445ShimRatReportertoolS0454CadelspymalwareS0456Aria-bodymalwareS0487KesselmalwareS0515WellMailmalwareS0517PillowmintmalwareS0521BloodHoundtoolS0567DtrackmalwareS0586TAINTEDSCRIBEmalwareS0622AppleSeedmalwareS0657BLUELIGHTmalwareS0658XCSSETmalwareS0667ChrommmemalwareS0681LizarmalwareS1012PowerLessmalwareS1039BumblebeemalwareS1101LoFiSemalwareS1140SpicamalwareS1148Raccoon StealermalwareS1196Troll StealermalwareS1206JumbledPathmalwareS9032MuddyVipermalwareS9036LP-Notesmalware

▪Reference

T1560on MITRE ATT&CK

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.