Cross-source coverage

T1002 / ATT&CK

Data Compressed

ATT&CK has retired this technique. Rules still tag it; the current id is T1560 Archive Collected Data.

4 rules · 2 families across 1 source.

3 deprecated hidden · include

From MITRE ATT&CK 19.2

An adversary may compress data (e.g., sensitive documents) that is collected prior to exfiltration in order to make it portable and minimize the amount of data sent over the network. The compression is done separately from the exfiltration channel and is performed using a custom program or algorithm, or a more common compression library or utility such as 7zip, RAR, ZIP, or zlib.

Tactics
Exfiltration
Platforms
Linux · Windows · macOS
Telemetry

Emerging Threats Open

4 rules · 2 families
Detection Severity Format
ET HUNTING Suspicious Zipped Filename in Outbound POST Request (google_chrome_default_) M1 2 variants High Suricata
ET HUNTING Suspicious Zipped Filename in Outbound POST Request (google_chrome_default_) M2 2 variants High Suricata
ET HUNTING Suspicious Zipped Filename in Outbound POST Request (Mozilla_Firefox_Cookies) M1 2 variants High Suricata
ET HUNTING Suspicious Zipped Filename in Outbound POST Request (Mozilla_Firefox_Cookies) M2 2 variants High Suricata

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.