kevmap

TechniquesT1560.001 › AN0833

AN0833 Analytic 0833

macOS · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Detects invocation of macOS-native archiving utilities (zip, ditto, hdiutil) or openssl used for encryption. Correlates execution with archive or encrypted file creation (.zip, .dmg, .tar.gz) in user or temporary directories. Identifies anomalous use of archiving commands by Office applications or daemons.</p>
Detects
T1560.001 Archive via Utility
Part of
DET0298 Detect Archiving via Utility (T1560.001)

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
macos:unifiedlogExecution of zip, ditto, hdiutil, or openssl by processes not normally associated with archivingDC0032 Process Creation
macos:unifiedlogCreation of .zip, .dmg, .tar.gz files in /Users, /tmp, or application directoriesDC0039 File Creation

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
AllowedArchiversBusiness-approved applications permitted to create archives (e.g., backup agents).
UserContextFlag archiving under privileged or service accounts as higher risk.
PayloadEntropyThresholdEntropy threshold for detecting encrypted archives versus normal compression.

KEV CVEs whose mapped technique this analytic detects

CVEVendor / productState
CVE-2021-40539Zoho ManageEngineMapped
CVE-2021-44077Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter PlusMapped