Archive Collected Data [T1560]
To conceal data, attackers may consolidate data into compressed archive files, such as Zip, RAR, TAR, or CAB files. To hunt for this obfuscation technique, use the files log.
To search for compressed files:
- Search the
fileslog, retrieving thetx_hosts,rx_hosts,mime_type,total_bytes, andsourcefields. - Remove records with uninteresting
mime_typesfrom the results, for example:
application/x-x509-*application/ocsp*image/*audio/*video/*text/*application/xmlapplication/chrome-ext
| Name | URL |
|---|---|
| Multiple Compressed Files Transferred Outbound | https://tdm.socprime.com/tdm/info/uslXmM2xWmWw |
| Multiple Compressed Files Transferred over HTTP | https://tdm.socprime.com/tdm/info/rJDgVmuJJCA7 |