Local Data Staging

T1074.001

Sub-technique of T1074 Data Staged.View on attack.mitre.org

About this technique

Adversaries may stage collected data in a central location or directory on the local system prior to Exfiltration. Data may be kept in separate files or combined into one file through techniques such as Archive Collected Data. Interactive command shells may be used, and common functionality within cmd and bash may be used to copy data into a staging location.

Adversaries may also stage collected data in various available formats/locations of a system, including local storage databases/repositories or the Windows Registry.

Detection rules5

Rules on DetectionCode tagged with T1074.001.

Sigma4

Splunk1

RuleTypeRiskData source
Shai-Hulud 2 Exfiltration Artifact FilesTTPNULLSysmon for Linux EventID 11, Sysmon EventID 11

Groups28

Show 4 more

Software95

Show 71 more

Campaigns13

Procedure examples136

Groups28

Used byProcedure example
GroupAgrius

Agrius has used the folder, C:\\windows\\temp\\s\\, to stage data for exfiltration.

GroupAPT28

APT28 has stored captured credential information in a file named pi.log.

GroupAPT3

APT3 has been known to stage files for exfiltration in a single location.

GroupAPT39

APT39 has utilized tools to aggregate data prior to exfiltration.

GroupAPT5

APT5 has staged data on compromised systems prior to exfiltration often in `C:\Users\Public`.

GroupBackdoorDiplomacy

BackdoorDiplomacy has copied files of interest to the main drive's recycle bin.

GroupChimera

Chimera has staged stolen data locally on compromised hosts.

GroupDragonfly

Dragonfly has created a directory named "out" in the user's %AppData% folder and copied files to it.

View all 28 groups examples

Software95

Used byProcedure example
MalwareADVSTORESHELL

ADVSTORESHELL stores output from command execution in a .dat file in the %TEMP% directory.

MalwareAppleSeed

AppleSeed can stage files in a central location prior to exfiltration.

MalwareAstaroth

Astaroth collects data in a plaintext file named r1.log before exfiltration.

MalwareAttor

Attor has staged collected data in a central upload directory prior to exfiltration.

MalwareAuTo Stealer

AuTo Stealer can store collected data from an infected host to a file named `Hostname_UserName.txt` prior to exfiltration.

MalwareBADNEWS

BADNEWS copies documents under 15MB found on the victim system to is the user's %temp%\SMB\ folder. It also copies files from USB devices to a predefined directory.

MalwareBadPatch

BadPatch stores collected data in log files before exfiltration.

MalwareBeaverTail

BeaverTail has staged collected data to the system’s temporary directory.

View all 95 software examples

Campaigns13

Used byProcedure example
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries compiled discovery data locally on the victim host in a file located within `C:\Windows\TEMP\outlog.txt`.

CampaignAnthropic AI-orchestrated Campaign

During the Anthropic AI-orchestrated Campaign, the adversary used Claude Code to stage extracted data and operational documentation in structured markdown files on local systems prior to exfiltration.

CampaignAPT28 Nearest Neighbor Campaign

During APT28 Nearest Neighbor Campaign, APT28 staged captured credential information in the C:\ProgramData directory.

CampaignAPT41 DUST

APT41 DUST involved exporting data from Oracle databases to local CSV files prior to exfiltration.

CampaignC0015

During C0015, PowerView's file share enumeration results were stored in the file `c:\ProgramData\found_shares.txt`.

CampaignC0017

During C0017, APT41 copied the local `SAM` and `SYSTEM` Registry hives to a staging directory.

CampaignC0032

During the C0032 campaign, TEMP.Veles used staging folders that are infrequently used by legitimate users or processes to store data for exfiltration and tool deployment.

CampaignJuicy Mix

During Juicy Mix, OilRig used browser data and credential stealer tools to stage stolen files named Cupdate, Eupdate, and IUpdate in the %TEMP% directory.

View all 13 campaigns examples

References1

  1. Prevailion DarkWatchman 2021 Open source
    Smith, S., Stafford, M. (2021, December 14). DarkWatchman: A new evolution in fileless techniques. Retrieved January 10, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.