MITRE ATT&CK · Enterprise

T1560.003 — Archive Collected Data: Archive via Custom Method

Sub-technique of T1560 Archive Collected Data

ID
T1560.003
Platforms
Linux, macOS, Windows
Tactics
Collection

Description

An adversary may compress or encrypt data that is collected prior to exfiltration using a custom method. Adversaries may choose to use custom archival methods, such as encryption with XOR or stream ciphers implemented with no external library or utility references. Custom implementations of well-known compression algorithms have also been used.

Detected by EasySIEM

This project's own SigmaHQ-derived detection pipeline tags every compiled rule with the ATT&CK technique(s) it maps to -- if a rule in your install covers this technique, its alerts show up automatically on your own EasySIEM Console's ATT&CK Reference page, no lookup needed. This page exists so a click from there always lands here on easysiem.com, not on attack.mitre.org.

View this technique on the official MITRE ATT&CK site ↗