Cross-source coverage
T1020 / ATT&CK
Automated Exfiltration
42 rules across 7 sources.
2 deprecated hidden · include
From MITRE ATT&CK 19.2
Adversaries may exfiltrate data, such as sensitive documents, through the use of automated processing after being gathered during Collection.
When automated exfiltration is used, other exfiltration techniques likely apply as well to transfer the information out of the network, such as Exfiltration Over C2 Channel and Exfiltration Over Alternative Protocol.
- Tactics
- Exfiltration
- Platforms
- Linux · macOS · Network Devices · Windows
- Telemetry
-
WinEventLog:SecurityWinEventLog:Sysmonauditd:SYSCALLNSM:Flowmacos:unifiedlogmacos:cron
How MITRE says to detect it DET0397
Automated Exfiltration Detection Strategy
Windows Analytic 1113
Detection of automated tools or scripts periodically transmitting data to external destinations using scheduled tasks or background processes.
WinEventLog:SecurityEventCode=4688WinEventLog:SysmonEventCode=3, 22
Linux Analytic 1114
Background scripts (e.g., via cron) or daemons transmitting data repeatedly to remote IPs or URLs.
auditd:SYSCALLexecveNSM:FlowOutbound Connections
macOS Analytic 1115
Observation of LaunchAgents or LaunchDaemons establishing periodic external connections indicative of automated data transfer.
macos:unifiedlogprocess: execmacos:unifiedlognetworkmacos:croncron/launchd
Sub-techniques with coverage
Counted in the 42 above — a rule tagged a sub-technique covers this technique too.
Azure/Azure-Sentinel
10 rules| Detection | Severity | Format |
|---|---|---|
| A host is potentially running a hacking tool (ASIM Web Session schema) | Medium | KQL |
| NRT Multiple users email forwarded to same destination | Medium | KQL |
| Users searching for VIP user activity | Low | KQL |
| Azure Storage File Create and Delete | Undefined | KQL |
| Cross workspace query anomolies | Undefined | KQL |
| Mass Downloads in the last 7 days | Undefined | KQL |
| New client running queries | Undefined | KQL |
| New Location Sign in with Mail forwarding activity | Undefined | KQL |
| New ServicePrincipal running queries | Undefined | KQL |
| User running multiple queries that fail | Undefined | KQL |
SigmaHQ/sigma
10 rules| Detection | Severity | Format |
|---|---|---|
| Modification or Deletion of an AWS RDS Cluster | High | Sigma |
| Restore Public AWS RDS Instance | High | Sigma |
| AWS RDS Master Password Change | Medium | Sigma |
| Github Fork Private Repositories Setting Enabled/Cleared | Medium | Sigma |
| Github Repository/Organization Transferred | Medium | Sigma |
| Mail Forwarding/Redirecting Activity In O365 | Medium | Sigma |
| Mail Forwarding/Redirecting Activity Via ExchangePowerShell Cmdlet | Medium | Sigma |
| PowerShell Script With File Hostname Resolving Capabilities | Medium | Sigma |
| PowerShell Script With File Upload Capabilities | Low | Sigma |
| Suspicious Inbox Forwarding | Low | Sigma |
elastic/detection-rules
7 rules| Detection | Severity | Format |
|---|---|---|
| AWS EC2 Full Network Packet Capture Detected | Medium | Elastic TOML |
| GitHub Exfiltration via High Number of Repository Clones by User | Medium | Elastic TOML |
| High Number of Closed Pull Requests by User | Medium | Elastic TOML |
| High Number of Protected Branch Force Pushes by User | Medium | Elastic TOML |
| M365 OneDrive/SharePoint Excessive File Downloads | Medium | Elastic TOML |
| Several Failed Protected Branch Force Pushes by User | Medium | Elastic TOML |
| GitHub Private Repository Turned Public | Low | Elastic TOML |
panther-labs/panther-analysis
6 rules| Detection | Severity | Format |
|---|---|---|
| AWS Public RDS Restore | High | Panther Python |
| Microsoft Exchange External Forwarding | High | Panther Python |
| Salesforce Bulk API Data Exfiltration | Medium | Panther Python |
| Salesforce OAuth Credential Abuse Detection | Medium | Panther Python |
| DEPRECATED - GitHub Web Hook Modified | Informational | Panther Python |
| GitHub Web Hook Modified | Informational | Panther Python |
socfortress/Wazuh-Rules
4 rules| Detection | Severity | Format |
|---|---|---|
| Sysmon - Event 1: Process creation · HTTP PUT via PowerShell (T1020) | High | Wazuh XML |
| Sysmon - Event 1: Process creation · PowerShell File Creation for Exfil (T1020) | High | Wazuh XML |
| Sysmon - Event 1: Process creation · PowerShell FTP Credential Use (T1020) | High | Wazuh XML |
| Sysmon - Event 1: Process creation · PowerShell FTP Exfiltration (T1020) | High | Wazuh XML |
splunk/security_content
4 rules| Detection | Severity | Format |
|---|---|---|
| Detect RClone Command-Line Usage | Undefined | SPL |
| Detect Renamed RClone | Undefined | SPL |
| Detect Traffic Mirroring | Undefined | SPL |
| Windows Mustang Panda USB Tool Execution | Undefined | SPL |
falcosecurity/rules
1 rule| Detection | Severity | Format |
|---|---|---|
| Launch Remote File Copy Tools in Container | Low | Falco YAML |