Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/T1560/T1560.001
MITRE ATT&CK Sub-Technique

T1560.001: Archive via Utility

ShareXLinkedInRedditHN

Adversaries may use utilities to compress and/or encrypt collected data prior to exfiltration. Many utilities include functionalities to compress, encrypt, or otherwise package data into a format that is easier/more secure to transport. Adversaries may abuse various utilities to compress or encrypt data before exfiltration. Some third party utilities may be preinstalled, such as <code>tar</code> on Linux and macOS or <code>zip</code> on Windows systems. On Windows, <code>diantz</code> or <code> makecab</code> may be used to package collected files into a cabinet (.cab) file. <code>diantz</code> may also be used to download and compress files from remote locations (i.e. [Remote Data Staging](https://attack.mitre.org/techniques/T1074/002)).(Citation: diantz.exe_lolbas) <code>xcopy</code> on Windows can copy files and directories with a variety of options. Additionally, adversaries may use [certutil](https://attack.mitre.org/software/S0160) to Base64 encode collected data before exfiltration. Adversaries may use also third party utilities, such as 7-Zip, WinRAR, and WinZip, to perform similar activities.(Citation: 7zip Homepage)(Citation: WinRAR Homepage)(Citation: WinZip Homepage)

Tactics
Collection
Platforms
Linux, macOS, Windows

▪Parent technique

T1560: Archive Collected Data

▪Mitigations (1)

M1047Audit

Auditing is the process of recording activity and systematically reviewing and analyzing the activity and system configurations. The primary purpose of auditing is to detect anomalies and identify potential threats or weaknesses in the environment. Proper auditing configurations can also help to meet compliance requirements. The process of auditing encompasses regular analysis of user behaviors and system logs in support of proactive security measures. Auditing is applicable to all systems used within an organization, from the front door of a building to accessing a file on a fileserver. It is considered more critical for regulated industries such as, healthcare, finance and government where compliance requirements demand stringent tracking of user and system activates.This mitigation can be implemented through the following measures: System Audit: - Use Case: Regularly assess system configurations to ensure compliance with organizational security policies. - Implementation: Use tools to scan for deviations from established benchmarks. Permission Audits: - Use Case: Review file and folder permissions to minimize the risk of unauthorized access or privilege escalation. - Implementation: Run access reviews to identify users or groups with excessive permissions. Software Audits: - Use Case: Identify outdated, unsupported, or insecure software that could serve as an attack vector. - Implementation: Use inventory and vulnerability scanning tools to detect outdated versions and recommend secure alternatives. Configuration Audits: - Use Case: Evaluate system and network configurations to ensure secure settings (e.g., disabled SMBv1, enabled MFA). - Implementation: Implement automated configuration scanning tools like SCAP (Security Content Automation Protocol) to identify non-compliant systems. Network Audits: - Use Case: Examine network traffic, firewall rules, and endpoint communications to identify unauthorized or insecure connections. - Implementation: Utilize tools such as Wireshark, or Zeek to monitor and log suspicious network behavior.

▪Used by groups (39)

G0004Ke3changG0006APT1G0007APT28G0010TurlaG0022APT3G0030Lotus BlossomG0045menuPassG0052CopyKittensG0054SowbugG0059Magic HoundG0060BRONZE BUTLERG0061FIN8G0064APT33G0069MuddyWaterG0084GallmakerG0087APT39G0093GALLIUMG0094KimsukyG0096APT41G0102Wizard SpiderG0114ChimeraG0117Fox KittenG0125HAFNIUMG0129Mustang PandaG0143Aquatic PandaG1006Earth LuscaG1016FIN13G1017Volt TyphoonG1022ToddyCatG1023APT5G1024AkiraG1030AgriusG1032INC RansomG1039RedCurlG1040PlayG1041Sea TurtleG1048UNC3886G1054MirrorFaceG1055VOID MANTICORE

▪Software using this technique (34)

S0062DustySkymalwareS0160certutiltoolS0187DaserfmalwareS0192PupytoolS0196PUNCHBUGGYmalwareS0212CORALDECKmalwareS0260InvisiMolemalwareS0264OopsIEmalwareS0274CalistomalwareS0278iKittenmalwareS0332RemcostoolS0339MicropsiamalwareS0340OctopusmalwareS0378PoshC2toolS0428PoetRATmalwareS0439OkrummalwareS0441PowerShowermalwareS0458RamsaymalwareS0466WindTailmalwareS0538CrutchmalwareS0622AppleSeedmalwareS0647TurianmalwareS1022IceApplemalwareS1040RclonetoolS1043ccf32malwareS1141LunarWebmalwareS1168SampleCheck5000malwareS1210SagerunexmalwareS1228PUBLOADmalwareS1239TONESHELLmalwareS1245InvisibleFerretmalwareS1246BeaverTailmalwareS9010GlassWormmalwareS9035LAMEHUGmalware

▪Reference

T1560.001on MITRE ATT&CK

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.