Cross-source coverage

T1002 / ATT&CK

Data Compressed

ATT&CK has retired this technique. Rules still tag it; the current id is T1560 Archive Collected Data.

7 rules · 5 families across 2 sources.

Showing deprecated rules · back to the default

From MITRE ATT&CK 19.2

An adversary may compress data (e.g., sensitive documents) that is collected prior to exfiltration in order to make it portable and minimize the amount of data sent over the network. The compression is done separately from the exfiltration channel and is performed using a custom program or algorithm, or a more common compression library or utility such as 7zip, RAR, ZIP, or zlib.

Tactics
Exfiltration
Platforms
Linux · Windows · macOS
Telemetry

Emerging Threats Open

4 rules · 2 families
Detection Severity Format
ET HUNTING Suspicious Zipped Filename in Outbound POST Request (google_chrome_default_) M1 2 variants High Suricata
ET HUNTING Suspicious Zipped Filename in Outbound POST Request (google_chrome_default_) M2 2 variants High Suricata
ET HUNTING Suspicious Zipped Filename in Outbound POST Request (Mozilla_Firefox_Cookies) M1 2 variants High Suricata
ET HUNTING Suspicious Zipped Filename in Outbound POST Request (Mozilla_Firefox_Cookies) M2 2 variants High Suricata

chronicle/detection-rules

3 rules
Detection Severity Format
data_compression_detector_sysmon_behavior Undefined YARA-L
north_korean_tunneling_tool__electricfish_detection_ar19129a Undefined YARA-L
suspicious_compression_tool_parameters Undefined YARA-L

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.