Compliance Node Overview
MITRE ATT&CK T1560 (Archive Collected Data) is an Enterprise Collection technique. An adversary may compress and/or encrypt data that is collected prior to exfiltration. Compressing the data can help to obfuscate the collected data and minimize the amount of data sent over the network. Encryption can be used to hide information that is being exfiltrated from detection or make exfiltration less conspicuous upon inspection by a defender. Both compression and encryption are done prior to exfiltration, and can be performed using a utility, 3rd party library, or custom method. ATT&CK documents 3 sub-techniques: T1560.001 Archive via Utility; T1560.002 Archive via Library; T1560.003 Archive via Custom Method. Affected platforms: Linux, macOS, Windows. MITRE-documented mitigations include M1047 Audit. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls CM-02, RA-05, SC-07, SI-03, SI-04.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1560/
SHA-256 integrity: d54f70c2424fe85607897c5cac4aa059353a12b31121218eab3dca6c6233b651
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1560: Archive Collected Data (https://attack.mitre.org/techniques/T1560/) with 3 sub-techniques
- MITRE ATT&CK Tactic TA0009: Collection (https://attack.mitre.org/tactics/TA0009/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.