MITRE ATT&CK CoA - T1560.001 - Archive via Utility
This playbook Remediates the Data Encrypted technique using intelligence-driven Courses of Action (COA) defined by Palo Alto Networks Unit 42 team. ***Disclaimer: This playbook does not simulate an attack using the specified technique, but follows the steps to remediation as defined by Palo Alto Networks Unit 42 team’s Actionable Threat Objects and Mitigations (ATOMs). Techniques Handled: - T1560.001: Archive Collected Data: Archive via Utility Kill Chain phases: - Exfiltration MITRE ATT&CK Description: An adversary may compress or encrypt data that is collected prior to exfiltration using 3rd party utilities. Many utilities exist that can archive data, including 7-Zip[1], WinRAR[2], and WinZip[3]. Most utilities include functionality to encrypt and/or compress data. Some 3rd party utilities may be preinstalled, such as tar on Linux and macOS or zip on Windows systems. Possible playbook uses: - The playbook can be used independently to handle and remediate the specific technique. - The playbook can be used as a part of the “Courses of Action - Defense Evasion” playbook to remediate techniques based on the kill chain phase. - The playbook can be used as a part of the “MITRE ATT&CK - Courses of Action” playbook, which can be triggered by different sources and accepts the technique MITRE ATT&CK ID as an input.
MITRE ATT&CK - Courses of Action · 7 tasks · 0 inputs · 1 output
Details
| ID | MITRE ATT&CK CoA - T1560.001 - Archive via Utility |
|---|---|
| From Version | 6.5.0 |
| Tasks | 7 |
README
This playbook Remediates the Data Encrypted technique using intelligence-driven Courses of Action (COA) defined by Palo Alto Networks Unit 42 team.
***Disclaimer: This playbook does not simulate an attack using the specified technique, but follows the steps to remediation as defined by Palo Alto Networks Unit 42 team’s Actionable Threat Objects and Mitigations (ATOMs).
Techniques Handled:
- T1560.001: Archive Collected Data: Archive via Utility
Kill Chain phases:
- Exfiltration
MITRE ATT&CK Description:
An adversary may compress or encrypt data that is collected prior to exfiltration using 3rd party utilities. Many utilities exist that can archive data, including 7-Zip[1], WinRAR[2], and WinZip[3]. Most utilities include functionality to encrypt and/or compress data.
Some 3rd party utilities may be preinstalled, such as tar on Linux and macOS or zip on Windows systems.
Possible playbook uses:
- The playbook can be used independently to handle and remediate the specific technique.
- The playbook can be used as a part of the “Courses of Action - Defense Evasion” playbook to remediate techniques based on the kill chain phase.
- The playbook can be used as a part of the “MITRE ATT&CK - Courses of Action” playbook, which can be triggered by different sources and accepts the technique MITRE ATT&CK ID as an input.
Dependencies
This playbook uses the following sub-playbooks, integrations, and scripts.
Sub-playbooks
This playbook does not use any sub-playbooks.
Integrations
This playbook does not use any integrations.
Scripts
- IsIntegrationAvailable
- Set
- SetGridField
Commands
This playbook does not use any commands.
Playbook Inputs
There are no inputs for this playbook.
Playbook Outputs
| Path | Description | Type |
|---|---|---|
| Handled.Techniques | The techniques handled in this playbook | unknown |
Playbook Image

Outputs
Handled.Techniques— The techniques handled in this playbook
Flowchart
description: "This playbook Remediates the Data Encrypted technique using intelligence-driven Courses of Action (COA) defined by Palo Alto Networks Unit 42 team.\n \n***Disclaimer: This playbook does not simulate an attack using the specified technique, but follows the steps to remediation as defined by Palo Alto Networks Unit 42 team’s Actionable Threat Objects and Mitigations (ATOMs).\nTechniques Handled:\n- T1560.001: Archive Collected Data: Archive via Utility\n\nKill Chain phases:\n- Exfiltration\n\nMITRE ATT&CK Description:\n\nAn adversary may compress or encrypt data that is collected prior to exfiltration using 3rd party utilities. Many utilities exist that can archive data, including 7-Zip[1], WinRAR[2], and WinZip[3]. Most utilities include functionality to encrypt and/or compress data.\n\nSome 3rd party utilities may be preinstalled, such as tar on Linux and macOS or zip on Windows systems.\n\nPossible playbook uses:\n- The playbook can be used independently to handle and remediate the specific technique.\n- The playbook can be used as a part of the “Courses of Action - Defense Evasion” playbook to remediate techniques based on the kill chain phase.\n- The playbook can be used as a part of the “MITRE ATT&CK - Courses of Action” playbook, which can be triggered by different sources and accepts the technique MITRE ATT&CK ID as an input." id: MITRE ATT&CK CoA - T1560.001 - Archive via Utility inputs: [] name: MITRE ATT&CK CoA - T1560.001 - Archive via Utility outputs: - contextPath: Handled.Techniques description: The techniques handled in this playbook type: unknown starttaskid: "0" tasks: "0": id: "0" ignoreworker: false nexttasks: '#none#': - "4" note: false quietmode: 0 separatecontext: false skipunavailable: false task: brand: "" id: 5b809bab-f4c5-4a90-8c1f-bafb142ee3ff iscommand: false name: "" version: -1 description: '' taskid: 5b809bab-f4c5-4a90-8c1f-bafb142ee3ff timertriggers: [] type: start view: |- { "position": { "x": 50, "y": -210 } } "1": id: "1" ignoreworker: false nexttasks: '#none#': - "3" note: false quietmode: 0 separatecontext: false skipunavailable: false task: brand: "" description: Manual - Configure XDR Behavioral Threat Protection under the Malware Security Profile. id: 6c1c7ea8-5c8f-4bae-8732-646e4c4e23a8 iscommand: false name: Manual - Configure XDR Behavioral Threat Protection under the Malware Security Profile type: regular version: -1 taskid: 6c1c7ea8-5c8f-4bae-8732-646e4c4e23a8 timertriggers: [] type: regular view: |- { "position": { "x": 50, "y": 275 } } "2": id: "2" ignoreworker: false note: false quietmode: 0 separatecontext: false skipunavailable: false task: brand: "" id: d456a2aa-325f-4479-80e9-8df5f18dce15 iscommand: false name: Done type: title version: -1 description: '' taskid: d456a2aa-325f-4479-80e9-8df5f18dce15 timertriggers: [] type: title view: |- { "position": { "x": 50, "y": 815 } } "3": id: "3" ignoreworker: false nexttasks: '#none#': - "6" note: false quietmode: 0 scriptarguments: append: simple: "true" key: simple: Handled.Techniques stringify: {} value: simple: '["T1022","T1560.001"]' separatecontext: false skipunavailable: false task: brand: "" description: Set a value in context under the key you entered. id: a65cdcf4-60cc-4ef9-838e-bda69c5aed05 iscommand: false name: Set technique handled script: Set type: regular version: -1 taskid: a65cdcf4-60cc-4ef9-838e-bda69c5aed05 timertriggers: [] type: regular view: |- { "position": { "x": 50, "y": 470 } } "4": id: "4" ignoreworker: false nexttasks: '#default#': - "5" "yes": - "1" note: false quietmode: 0 scriptarguments: brandname: simple: Cortex XDR - IR separatecontext: false skipunavailable: false task: brand: "" description: Returns 'yes' if integration brand is available. Otherwise returns 'no' id: c42020ca-137b-47b8-8b0b-8b999429a300 iscommand: false name: Is Cortex XDR integration Enabled? script: IsIntegrationAvailable type: condition version: -1 taskid: c42020ca-137b-47b8-8b0b-8b999429a300 timertriggers: [] type: condition view: |- { "position": { "x": 50, "y": -70 } } "5": id: "5" ignoreworker: false nexttasks: '#none#': - "1" note: false quietmode: 0 separatecontext: false skipunavailable: false task: brand: "" description: | Enable the Cortex XDR integration to follow this CoA. If needed - please contact your Palo Alto Networks account manager for future guidance and assistance. id: 10cf7b7d-0ee8-4212-8a35-d21ecfc8dc8e iscommand: false name: Manual - Enable Cortex XDR integration type: regular version: -1 taskid: 10cf7b7d-0ee8-4212-8a35-d21ecfc8dc8e timertriggers: [] type: regular view: |- { "position": { "x": 430, "y": 100 } } "6": continueonerror: true id: "6" ignoreworker: false nexttasks: '#none#': - "2" note: false quietmode: 0 scriptarguments: columns: simple: technique context_path: simple: Handled.Techniques grid_id: simple: handledtechniques keys: {} overwrite: {} sort_by: {} unpack_nested_elements: {} separatecontext: false skipunavailable: false task: brand: "" description: Creates a Grid table from items or key-value pairs. id: 82331e54-b12b-4034-8e43-544272f6965a iscommand: false name: Set grid field script: SetGridField type: regular version: -1 taskid: 82331e54-b12b-4034-8e43-544272f6965a timertriggers: [] type: regular view: |- { "position": { "x": 50, "y": 640 } } version: -1 view: |- { "linkLabelsPosition": { "4_1_yes": 0.57 }, "paper": { "dimensions": { "height": 1090, "width": 760, "x": 50, "y": -210 } } } tests: - No tests (auto formatted) fromversion: 6.5.0