Tactic.View on attack.mitre.org
The adversary is trying to steal data.
Exfiltration consists of techniques that adversaries may use to steal data from your network. Once they’ve collected data, adversaries often package it to avoid detection while removing it. This can include compression and encryption. Techniques for getting data out of a target network typically include transferring it over their command and control channel or an alternate channel and may also include putting size limits on the transmission.
| ID | Name | Sub-techniques | Examples |
|---|---|---|---|
| T1011 | Exfiltration Over Other Network Medium | 1 | 1 |
| T1020 | Automated Exfiltration | 1 | 31 |
| T1029 | Scheduled Transfer | 0 | 18 |
| T1030 | Data Transfer Size Limits | 0 | 21 |
| T1041 | Exfiltration Over C2 Channel | 0 | 203 |
| T1048 | Exfiltration Over Alternative Protocol | 3 | 52 |
| T1052 | Exfiltration Over Physical Medium | 1 | 7 |
| T1537 | Transfer Data to Cloud Account | 0 | 3 |
| T1567 | Exfiltration Over Web Service | 4 | 66 |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.