{"id":"T1560.002","name":"Archive via Library","url":"https://attack.mitre.org/techniques/T1560/002","tactics":["collection"],"platforms":["Linux","macOS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0268","stix_id":"x-mitre-detection-strategy--a3dcb195-d1b5-4bce-b62b-ba9bdaed56d5","name":"Detect Archiving via Library (T1560.002)","url":"https://attack.mitre.org/detectionstrategies/DET0268","analytics":[{"id":"AN0747","stix_id":"x-mitre-analytic--4bdc0555-f7f0-4b5b-80c9-77f361881a01","name":"Analytic 0747","description":"Detects adversarial archiving using libraries (zlib, zip APIs) invoked by scripts or binaries. Correlates process executions of Python, PowerShell, or custom .NET binaries with DLL/module loads linked to compression libraries, followed by archive file creation.","url":"https://attack.mitre.org/detectionstrategies/DET0268#AN0747","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4688","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Sysmon","channel":"EventCode=7","data_component":"DC0016","data_component_name":"Module Load","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=11","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"LibraryAllowlist","description":"Known business applications using compression libraries."},{"field":"SuspiciousExtensions","description":"Archive extensions considered sensitive in monitored environments."},{"field":"TimeWindow","description":"Correlation window between script/library invocation and file creation."}],"live":true,"detection_strategies":["DET0268"],"techniques":["T1560.002"]},{"id":"AN0748","stix_id":"x-mitre-analytic--90e51090-9857-4a28-98b9-f21401ddbe85","name":"Analytic 0748","description":"Detects adversarial archiving by scripts or binaries calling compression libraries (libzip, zlib, bzip2). Correlates execution of Python, Perl, or compiled binaries with dynamic linking to archiving libraries and creation of compressed files in /tmp or user directories.","url":"https://attack.mitre.org/detectionstrategies/DET0268#AN0748","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve: Execution of python, perl, or custom binaries invoking compression libraries","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"auditd-syscall"},{"name":"auditd:MMAP","channel":"load: Loading of libzip.so, libz.so, or libbz2.so by processes not normally associated with archiving","data_component":"DC0016","data_component_name":"Module Load","log_source_slug":"auditd-mmap"},{"name":"auditd:FILE","channel":"create: Creation of .zip, .gz, .bz2 files in /tmp, /var/tmp, or /home directories","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"auditd-file"}],"mutable_elements":[{"field":"MonitoredLibraries","description":"List of shared objects linked to compression/encryption."},{"field":"ArchivePaths","description":"Directories where archive creation is flagged as anomalous."},{"field":"EntropyThreshold","description":"Entropy level used to distinguish encryption from normal compression."}],"live":true,"detection_strategies":["DET0268"],"techniques":["T1560.002"]},{"id":"AN0749","stix_id":"x-mitre-analytic--4ecd8727-bcf3-4fce-8c04-e8d0bad1267e","name":"Analytic 0749","description":"Detects malicious archiving via system or third-party libraries (libz, libarchive) invoked by Python, Swift, or Objective-C binaries. Correlates unified logs of library loads with creation of compressed or encrypted archives (.zip, .gz, .bz2, .dmg).","url":"https://attack.mitre.org/detectionstrategies/DET0268#AN0749","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"Execution of Python, Swift, or other binaries invoking archiving libraries","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"Loading of libz.dylib, libarchive.dylib by non-standard applications","data_component":"DC0016","data_component_name":"Module Load","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"Creation of .zip, .gz, .dmg archives in /Users, /tmp, or application directories","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"AllowedProcesses","description":"Applications allowed to load compression libraries (e.g., backup agents)."},{"field":"UserContext","description":"Flag archiving under privileged or system accounts as suspicious."},{"field":"FileExtensionFilter","description":"Targeted monitoring of sensitive file formats or compressed containers."}],"live":true,"detection_strategies":["DET0268"],"techniques":["T1560.002"]}],"live":true,"version":"1.0","techniques":["T1560.002"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}