Threadlinqs IntelligenceStart free

ATT&CK techniqueCollection

T1074.001 Local Data Staging

CollectionEnterpriseSub-technique

As of 2026-10-05, T1074.001 (Local Data Staging) appears in 66 tracked threats, first reported 2026-02-04 and most recently 2026-09-27, with linked actors including APT28, APT38, Sapphire Sleet; it most often appears alongside T1005 (Data from Local System).

Tracked threats
6612 critical, 47 high, 7 medium
First seen
2026-02-04
Last seen
2026-09-27
Threat actors
35In the threats using it
Detection rules
137Blue tier and above

Data as of:

Activity timeline

T1074.001 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 32 reports, and 66 of the 66 threats were reported in the twelve months to 2026-09.

How adversaries use it

T1074.001 Local Data Staging is catalogued by MITRE ATT&CK under the Collection tactic in the Enterprise matrix, as a sub-technique of T1074 Data Staged. Threadlinqs maps 66 of 2623 tracked threats (2.5%) to it; by severity that is 12 critical, 47 high, 7 medium.

Threats that use T1074.001 most often also use T1005 Data from Local System (50 threats), T1071.001 Web Protocols (49 threats), T1041 Exfiltration Over C2 Channel (41 threats), T1082 System Information Discovery (39 threats), T1027 Obfuscated Files or Information (38 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

35 tracked threat actors appear in the threats that use T1074.001; the most frequent are APT28 (3), APT38 (3), Sapphire Sleet (3), Stardust Chollima (3), BlueDelta (2).

Data sources

Telemetry that can reveal T1074.001, per MITRE ATT&CK.

  • Command — Command Execution
  • File — File Access, File Creation
  • Windows Registry — Windows Registry Key Modification

Threat actors using it

Tracked threats

The 30 most recent of 66 tracked threats that use T1074.001.

Detection coverage

Threadlinqs maintains 137 detection rules mapped to T1074.001 (SPL 45, KQL 47, Sigma 45). Rule content is available to Blue tier accounts and above; this page shows counts only.

137 detection rules (SPL/KQL/Sigma) · Blue and above. Compare plans

Parent technique

T1074 Data Staged — 120 tracked threats at the technique level.