Archive via Utility (T1560.001)

View on ATT&CK

In Playbook

Technique & Subtechniques

Associated Tactics

  • Collection

Collection (TA0009)

The adversary is trying to gather data of interest to their goal. Collection consists of techniques adversaries may use to gather information and the sources information is collected from that are relevant to following through on the adversary's objectives. Frequently, the next goal after collecting data is to either steal (exfiltrate) the data or to use the data to gain more information about the target environment. Common target sources include various drive types, browsers, audio, video, and email. Common collection methods include capturing screenshots and keyboard input.

View on ATT&CK

Procedure Examples

Description Source(s)
A. Roshal. (2020). RARLAB. Retrieved February 20, 2020. WinRAR Homepage
Corel Corporation. (2020). WinZip. Retrieved February 20, 2020. WinZip Homepage
I. Pavlov. (2019). 7-Zip. Retrieved February 20, 2020. 7zip Homepage
Living Off The Land Binaries, Scripts and Libraries (LOLBAS). (n.d.). Diantz.exe. Retrieved October 25, 2021. diantz.exe_lolbas
Wikipedia. (2016, March 31). List of file signatures. Retrieved April 22, 2016. Wikipedia File Header Signatures