{"id":"T1560.003","name":"Archive via Custom Method","url":"https://attack.mitre.org/techniques/T1560/003","tactics":["collection"],"platforms":["Linux","macOS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0438","stix_id":"x-mitre-detection-strategy--edf894b7-052a-4baf-8984-f01ec773c80c","name":"Detect Archiving via Custom Method (T1560.003)","url":"https://attack.mitre.org/detectionstrategies/DET0438","analytics":[{"id":"AN1213","stix_id":"x-mitre-analytic--3f47f3e9-2856-4830-9762-7ca0c3924f6d","name":"Analytic 1213","description":"Detects suspicious custom compression/encryption routines through anomalous script or binary execution that produces high-entropy files without standard archiving utilities. Correlates script execution, memory API usage (bitwise ops, CryptoAPI calls), and creation of archive-like files with uncommon headers.","url":"https://attack.mitre.org/detectionstrategies/DET0438#AN1213","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4688","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Sysmon","channel":"EventCode=11","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=10","data_component":"DC0035","data_component_name":"Process Access","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"EntropyThreshold","description":"Minimum entropy level that flags suspicious custom archives."},{"field":"AllowedProcesses","description":"Known business processes performing encryption or compression."},{"field":"TimeWindow","description":"Correlation timeframe between script execution and file creation."}],"live":true,"detection_strategies":["DET0438"],"techniques":["T1560.003"]},{"id":"AN1214","stix_id":"x-mitre-analytic--32ca8e2c-9c1e-4883-aa98-439efbfc76e4","name":"Analytic 1214","description":"Detects custom archive routines by correlating script execution (Python, Perl, Bash) with creation of high-entropy files in temporary or user directories. Flags processes performing unusual bitwise operations or writing files without standard compression headers.","url":"https://attack.mitre.org/detectionstrategies/DET0438#AN1214","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve: Execution of interpreters creating archive-like outputs without calling tar/gzip","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"auditd-syscall"},{"name":"auditd:FILE","channel":"create: Creation of files with anomalous headers and entropy levels in /tmp or user directories","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"auditd-file"},{"name":"linux:osquery","channel":"Detection of bitwise operations or custom encryption functions in memory traces","data_component":"DC0020","data_component_name":"Process Modification","log_source_slug":"linux-osquery"}],"mutable_elements":[{"field":"ArchivePaths","description":"Directories monitored for anomalous archive creation (e.g., /tmp, /home)."},{"field":"EntropyThreshold","description":"Entropy score to flag files lacking recognizable compression headers."},{"field":"ScriptAllowlist","description":"Scripts/processes known to use custom compression methods."}],"live":true,"detection_strategies":["DET0438"],"techniques":["T1560.003"]},{"id":"AN1215","stix_id":"x-mitre-analytic--1a39005f-28e7-4b07-85e2-14ffa0f6ea3b","name":"Analytic 1215","description":"Detects custom archiving by monitoring execution of Swift/Objective-C apps or scripts producing high-entropy files with non-standard headers. Correlates unified logs of abnormal NSFileHandle/NSData operations, memory use of XOR/bitwise operations, and file creation events.","url":"https://attack.mitre.org/detectionstrategies/DET0438#AN1215","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"Suspicious Swift/Objective-C or scripting processes writing archive-like outputs","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"Creation of files with anomalous headers and entropy values","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"Abnormal memory operations (XOR/bitwise loops) during archive generation","data_component":"DC0020","data_component_name":"Process Modification","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"UserContext","description":"Flag if archiving occurs under privileged/system accounts."},{"field":"EntropyThreshold","description":"Entropy score cutoff for identifying custom compressed or encrypted files."},{"field":"AllowedApps","description":"Applications legitimately using custom archiving for business purposes."}],"live":true,"detection_strategies":["DET0438"],"techniques":["T1560.003"]}],"live":true,"version":"1.0","techniques":["T1560.003"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}