T1020 Automated Exfiltration — ATT&CK Technique
Adversaries may exfiltrate data, such as sensitive documents, through the use of automated processing after being gathered during Collection. When automated exfiltration is used, other exfiltration techniques likely apply as well to transfer the information out of the network, such as Exfiltration Over C2 Channel and Exfiltration Over Alternative Protocol.
Detection coverage (13)
- Mail Forwarding/Redirecting Activity In O365 medium
- Mail Forwarding/Redirecting Activity Via ExchangePowerShell Cmdlet medium
- Github Fork Private Repositories Setting Enabled/Cleared medium
- Github Repository/Organization Transferred medium
- Modification or Deletion of an AWS RDS Cluster high
- AWS RDS Master Password Change medium
- Restore Public AWS RDS Instance high
- Suspicious Inbox Forwarding low
- PowerShell Script With File Hostname Resolving Capabilities medium
- PowerShell Script With File Upload Capabilities low
- Detect RClone Command-Line Usage
- Detect Renamed RClone
- Windows Mustang Panda USB Tool Execution
Malware using this technique
- StrongPity
- LightNeuron
- TajMahal
- Empire
- Doki
- Rover
- OutSteel
- Peppy
- Machete
- Ebury
- Raccoon Stealer
- Solar
- Hannotog
- USBStealer
- Crutch
- ShimRatReporter
- CosmicDuke
- Attor
- StrelaStealer
- TINYTYPHON