Cross-source coverage

T1020 / ATT&CK

Automated Exfiltration

42 rules across 7 sources.

2 deprecated hidden · include

From MITRE ATT&CK 19.2

Adversaries may exfiltrate data, such as sensitive documents, through the use of automated processing after being gathered during Collection.

When automated exfiltration is used, other exfiltration techniques likely apply as well to transfer the information out of the network, such as Exfiltration Over C2 Channel and Exfiltration Over Alternative Protocol.

Tactics
Exfiltration
Platforms
Linux · macOS · Network Devices · Windows
Telemetry
WinEventLog:SecurityWinEventLog:Sysmonauditd:SYSCALLNSM:Flowmacos:unifiedlogmacos:cron

How MITRE says to detect it DET0397

Automated Exfiltration Detection Strategy

Windows Analytic 1113

Detection of automated tools or scripts periodically transmitting data to external destinations using scheduled tasks or background processes.

  • WinEventLog:Security EventCode=4688
  • WinEventLog:Sysmon EventCode=3, 22

Linux Analytic 1114

Background scripts (e.g., via cron) or daemons transmitting data repeatedly to remote IPs or URLs.

  • auditd:SYSCALL execve
  • NSM:Flow Outbound Connections

macOS Analytic 1115

Observation of LaunchAgents or LaunchDaemons establishing periodic external connections indicative of automated data transfer.

  • macos:unifiedlog process: exec
  • macos:unifiedlog network
  • macos:cron cron/launchd

Sub-techniques with coverage

Counted in the 42 above — a rule tagged a sub-technique covers this technique too.


Azure/Azure-Sentinel

10 rules
Detection Severity Format
A host is potentially running a hacking tool (ASIM Web Session schema) Medium KQL
NRT Multiple users email forwarded to same destination Medium KQL
Users searching for VIP user activity Low KQL
Azure Storage File Create and Delete Undefined KQL
Cross workspace query anomolies Undefined KQL
Mass Downloads in the last 7 days Undefined KQL
New client running queries Undefined KQL
New Location Sign in with Mail forwarding activity Undefined KQL
New ServicePrincipal running queries Undefined KQL
User running multiple queries that fail Undefined KQL

SigmaHQ/sigma

10 rules
Detection Severity Format
Modification or Deletion of an AWS RDS Cluster High Sigma
Restore Public AWS RDS Instance High Sigma
AWS RDS Master Password Change Medium Sigma
Github Fork Private Repositories Setting Enabled/Cleared Medium Sigma
Github Repository/Organization Transferred Medium Sigma
Mail Forwarding/Redirecting Activity In O365 Medium Sigma
Mail Forwarding/Redirecting Activity Via ExchangePowerShell Cmdlet Medium Sigma
PowerShell Script With File Hostname Resolving Capabilities Medium Sigma
PowerShell Script With File Upload Capabilities Low Sigma
Suspicious Inbox Forwarding Low Sigma

elastic/detection-rules

7 rules
Detection Severity Format
AWS EC2 Full Network Packet Capture Detected Medium Elastic TOML
GitHub Exfiltration via High Number of Repository Clones by User Medium Elastic TOML
High Number of Closed Pull Requests by User Medium Elastic TOML
High Number of Protected Branch Force Pushes by User Medium Elastic TOML
M365 OneDrive/SharePoint Excessive File Downloads Medium Elastic TOML
Several Failed Protected Branch Force Pushes by User Medium Elastic TOML
GitHub Private Repository Turned Public Low Elastic TOML

panther-labs/panther-analysis

6 rules
Detection Severity Format
AWS Public RDS Restore High Panther Python
Microsoft Exchange External Forwarding High Panther Python
Salesforce Bulk API Data Exfiltration Medium Panther Python
Salesforce OAuth Credential Abuse Detection Medium Panther Python
DEPRECATED - GitHub Web Hook Modified Informational Panther Python
GitHub Web Hook Modified Informational Panther Python

socfortress/Wazuh-Rules

4 rules
Detection Severity Format
Sysmon - Event 1: Process creation · HTTP PUT via PowerShell (T1020) High Wazuh XML
Sysmon - Event 1: Process creation · PowerShell File Creation for Exfil (T1020) High Wazuh XML
Sysmon - Event 1: Process creation · PowerShell FTP Credential Use (T1020) High Wazuh XML
Sysmon - Event 1: Process creation · PowerShell FTP Exfiltration (T1020) High Wazuh XML

splunk/security_content

4 rules
Detection Severity Format
Detect RClone Command-Line Usage Undefined SPL
Detect Renamed RClone Undefined SPL
Detect Traffic Mirroring Undefined SPL
Windows Mustang Panda USB Tool Execution Undefined SPL

falcosecurity/rules

1 rule
Detection Severity Format
Launch Remote File Copy Tools in Container Low Falco YAML

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.