Technique with 1 sub-technique.View on attack.mitre.org
Adversaries may exfiltrate data, such as sensitive documents, through the use of automated processing after being gathered during Collection.
When automated exfiltration is used, other exfiltration techniques likely apply as well to transfer the information out of the network, such as Exfiltration Over C2 Channel and Exfiltration Over Alternative Protocol.
Rules on DetectionCode tagged with T1020 or one of its sub-techniques.
| Rule | Level | Log source | Technique |
|---|---|---|---|
| Modification or Deletion of an AWS RDS Cluster | high | aws / NULL | T1020 |
| Restore Public AWS RDS Instance | high | aws / NULL | T1020 |
| AWS RDS Master Password Change | medium | aws / NULL | T1020 |
| Github Fork Private Repositories Setting Enabled/Cleared | medium | github / NULL | T1020 |
| Github Repository/Organization Transferred | medium | github / NULL | T1020 |
| PowerShell Script With File Hostname Resolving Capabilities | medium | windows / ps_script | T1020 |
| PowerShell Script With File Upload Capabilities | low | windows / ps_script | T1020 |
| Suspicious Inbox Forwarding | low | m365 / NULL | T1020 |
| Rule | Type | Risk | Data source | Technique |
|---|---|---|---|---|
| Detect RClone Command-Line Usage | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2, Cisco Network Visibility Module Flow Data | T1020 |
| Detect Renamed RClone | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1020 |
| Detect Traffic Mirroring | TTP | NULL | Cisco IOS Logs | T1020.001 |
| Windows Mustang Panda USB Tool Execution | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1020 |
| ID | Name | Examples |
|---|---|---|
| T1020.001 | Traffic Duplication | 0 |
| Used by | Procedure example |
|---|---|
| GroupGamaredon Group | Gamaredon Group has used modules that automatically upload gathered documents to the C2 server. |
| GroupKe3chang | Ke3chang has performed frequent and scheduled data exfiltration from compromised networks. |
| GroupKimsuky | Kimsuky has exfiltrated data to C2 servers using an automated script that executes every 10 minutes and after successful checks for the presence of pre-designated staged filenames. |
| GroupRedCurl | RedCurl has used batch scripts to exfiltrate data. |
| GroupSidewinder | Sidewinder has configured tools to automatically send collected files to attacker controlled servers. |
| GroupTropic Trooper | Tropic Trooper has used a copy function to automatically exfiltrate sensitive data from air-gapped systems using USB storage. |
| GroupWinter Vivern | Winter Vivern delivered a PowerShell script capable of recursively scanning victim machines looking for various file types before exfiltrating identified files via HTTP. |
| Used by | Procedure example |
|---|---|
| MalwareAttor | Attor has a file uploader plugin that automatically exfiltrates the collected data and log files to the C2 server. |
| MalwareCosmicDuke | CosmicDuke exfiltrates collected files automatically over FTP to remote servers. |
| MalwareCrutch | Crutch has automatically exfiltrated stolen files to Dropbox. |
| MalwareDoki | Doki has used a script that gathers information from a hardcoded list of IP addresses and uploads to an Ngrok URL. |
| MalwareEbury | If credentials are not collected for two weeks, Ebury encrypts the credentials using a public key and sends them via UDP to an IP address located in the DNS TXT record. |
| ToolEmpire | Empire has the ability to automatically send collected data back to the threat actors' C2. |
| MalwareHannotog | Hannotog can upload encyrpted data for exfiltration. |
| MalwareLightNeuron | LightNeuron can be configured to automatically exfiltrate files under a specified directory. |
| Used by | Procedure example |
|---|---|
| CampaignArcaneDoor | ArcaneDoor included scripted exfiltration of collected data. |
| CampaignFrankenstein | During Frankenstein, the threat actors collected information via Empire, which was automatically sent back to the adversary's C2. |
| CampaignSalesforce Data Exfiltration | During Salesforce Data Exfiltration, threat actors used API queries to automatically exfiltrate large volumes of data. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.