Data Staged T1074
Tactic: Collection
Adversaries may stage collected data in a central location or directory prior to Exfiltration. Data may be kept in separate files or combined into one file through techniques such as Archive Collected Data. Interactive command shells may be used, and common functionality within cmd and bash may be used to copy data into a staging location.
Events covered
10 catalog events are tagged with this technique by at least one rule.
| Provider | Event | Title |
|---|---|---|
| Sysmon | Event ID 1 | Process creation |
| Sysmon | Event ID 11 | FileCreate |
| Security-Auditing | Event ID 4688 | A new process has been created. |
| Security-Auditing | Event ID 5145 | A network share object was checked to see whether client can be granted desired access. |
| ESF | exec | Process Execution |
| ESF | open | File Open |
| ESF | write | File Write |
| PowerShell | Event ID 4103 | Payload Context: ContextInfo User Data: UserData. |
| PowerShell | Event ID 4104 | Creating Scriptblock text (MessageNumber of MessageTotal). |
| Sysmon-for-Linux | Event ID 11 | File created |
Authoring guide
These 41 rules share fields, values, and exclusions.
Fields filtered most (49 distinct)
These fields appear most often in rule filters.
Top indicator values (354 distinct)
These values appear most often in rule predicates.
Exclusions (79 distinct)
These values appear most often in top-level exclusions.
Rules under this technique
These vendors publish rules tagged with this technique.
Sigma 6 rules
- Cisco Stage Data
- Folder Compress To Potentially Suspicious Output Via Compress-Archive Cmdlet
- Google Full Network Traffic Packet Capture
- Zip A Folder With PowerShell For Staging In Temp - PowerShell Module
- Zip A Folder With PowerShell For Staging In Temp - PowerShell
- Zip A Folder With PowerShell For Staging In Temp - PowerShell Script
Elastic 18 rules
- AWS EC2 Full Network Packet Capture Detected
- AWS RDS DB Instance Restored
- Data Encrypted and Archived
- Data Encrypted and Archived
- Data Encrypted via OpenSSL Utility
- Discovery Command Output Written to Suspicious File
- Environment Variable Secret Collection
- Exchange Mailbox Export via PowerShell
- File Compressed or Archived into Common Format by Unsigned Process
- File Staged in Root Folder of Recycle Bin
- Google Workspace Drive Data Transfer or Takeout Export Initiated
- Information Stealer Collection via Find
- Multi-Value Secret Searching via Find
- Multi-Value Secret Searching via Grep
- Potential OpenSSH Backdoor Logging Activity
- Remote File Copy to a Hidden Share
- Sensitive File Access followed by Compression
- Suspicious Archive Creation via Ditto
Splunk 11 rules
- Command Output Redirected to Localhost (Windows Event Log)
- Data Staged to File (PowerShell)
- Data Staged to File (Sysmon)
- Data Staged to File (Windows Event Log)
- Native Archive Commands (PowerShell)
- Native Archive Commands (Sysmon)
- Native Archive Commands (Windows Event Log)
- Output to File (PowerShell)
- Output to File (Windows Event Log)
- Shai-Hulud 2 Exfiltration Artifact Files
- Suspicious SQLite3 LSQuarantine Behavior
Kusto 4 rules
- Netskope - Anomalous User Behavior (High Volume from Unmanaged Device)
- Netskope - Data Movement Tracking (Upload/Download Monitoring)
- Netskope - Excessive Downloads Detection (Spike vs Baseline)
- NordPass - User deletes items in bulk