Sub-technique of T1074 Data Staged.View on attack.mitre.org
Adversaries may stage collected data in a central location or directory on the local system prior to Exfiltration. Data may be kept in separate files or combined into one file through techniques such as Archive Collected Data. Interactive command shells may be used, and common functionality within cmd and bash may be used to copy data into a staging location.
Adversaries may also stage collected data in various available formats/locations of a system, including local storage databases/repositories or the Windows Registry.
Rules on DetectionCode tagged with T1074.001.
| Rule | Level | Log source |
|---|---|---|
| Folder Compress To Potentially Suspicious Output Via Compress-Archive Cmdlet | medium | windows / process_creation |
| Zip A Folder With PowerShell For Staging In Temp - PowerShell Module | medium | windows / ps_module |
| Zip A Folder With PowerShell For Staging In Temp - PowerShell | medium | windows / NULL |
| Zip A Folder With PowerShell For Staging In Temp - PowerShell Script | medium | windows / ps_script |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Shai-Hulud 2 Exfiltration Artifact Files | TTP | NULL | Sysmon for Linux EventID 11, Sysmon EventID 11 |
| Used by | Procedure example |
|---|---|
| GroupAgrius | Agrius has used the folder, |
| GroupAPT28 | APT28 has stored captured credential information in a file named pi.log. |
| GroupAPT3 | APT3 has been known to stage files for exfiltration in a single location. |
| GroupAPT39 | APT39 has utilized tools to aggregate data prior to exfiltration. |
| GroupAPT5 | APT5 has staged data on compromised systems prior to exfiltration often in `C:\Users\Public`. |
| GroupBackdoorDiplomacy | BackdoorDiplomacy has copied files of interest to the main drive's recycle bin. |
| GroupChimera | Chimera has staged stolen data locally on compromised hosts. |
| GroupDragonfly | Dragonfly has created a directory named "out" in the user's %AppData% folder and copied files to it. |
| Used by | Procedure example |
|---|---|
| MalwareADVSTORESHELL | ADVSTORESHELL stores output from command execution in a .dat file in the %TEMP% directory. |
| MalwareAppleSeed | AppleSeed can stage files in a central location prior to exfiltration. |
| MalwareAstaroth | Astaroth collects data in a plaintext file named r1.log before exfiltration. |
| MalwareAttor | Attor has staged collected data in a central upload directory prior to exfiltration. |
| MalwareAuTo Stealer | AuTo Stealer can store collected data from an infected host to a file named `Hostname_UserName.txt` prior to exfiltration. |
| MalwareBADNEWS | BADNEWS copies documents under 15MB found on the victim system to is the user's |
| MalwareBadPatch | BadPatch stores collected data in log files before exfiltration. |
| MalwareBeaverTail | BeaverTail has staged collected data to the system’s temporary directory. |
| Used by | Procedure example |
|---|---|
| Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries compiled discovery data locally on the victim host in a file located within `C:\Windows\TEMP\outlog.txt`. |
| CampaignAnthropic AI-orchestrated Campaign | During the Anthropic AI-orchestrated Campaign, the adversary used Claude Code to stage extracted data and operational documentation in structured markdown files on local systems prior to exfiltration. |
| CampaignAPT28 Nearest Neighbor Campaign | During APT28 Nearest Neighbor Campaign, APT28 staged captured credential information in the |
| CampaignAPT41 DUST | APT41 DUST involved exporting data from Oracle databases to local CSV files prior to exfiltration. |
| CampaignC0015 | During C0015, PowerView's file share enumeration results were stored in the file `c:\ProgramData\found_shares.txt`. |
| CampaignC0017 | During C0017, APT41 copied the local `SAM` and `SYSTEM` Registry hives to a staging directory. |
| CampaignC0032 | During the C0032 campaign, TEMP.Veles used staging folders that are infrequently used by legitimate users or processes to store data for exfiltration and tool deployment. |
| CampaignJuicy Mix | During Juicy Mix, OilRig used browser data and credential stealer tools to stage stolen files named Cupdate, Eupdate, and IUpdate in the %TEMP% directory. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.