Cross-source coverage
T1567 / ATT&CK
Exfiltration Over Web Service
173 rules across 9 sources.
6 deprecated hidden · include
Showing atomic-IOC rules · back to the default
From MITRE ATT&CK 19.2
Adversaries may use an existing, legitimate external Web service to exfiltrate data rather than their primary command and control channel. Popular Web services acting as an exfiltration mechanism may give a significant amount of cover due to the likelihood that hosts within a network are already communicating with them prior to compromise. Firewall rules may also already exist to permit traffic to these services.
Web service providers also commonly use SSL/TLS encryption, giving adversaries an added level of protection.
- Tactics
- Exfiltration
- Platforms
- ESXi · Linux · macOS · Office Suite · SaaS · Windows
- Telemetry
-
WinEventLog:SecurityWinEventLog:Sysmonauditd:EXECVEauditd:SYSCALLNSM:Flowmacos:unifiedlogm365:unifiedsaas:boxesxi:vmkernelesxi:hostd
How MITRE says to detect it DET0548
Detection Strategy for Exfiltration Over Web Service
Windows Analytic 1511
Processes that normally do not initiate network communications suddenly making outbound HTTPS connections with high outbound-to-inbound data ratios. Defender view: correlation between process creation logs (e.g., Word, Excel, PowerShell) and subsequent anomalous network traffic volumes toward common web services (Dropbox, Google Drive, OneDrive).
WinEventLog:SecurityEventCode=4688WinEventLog:SysmonEventCode=3, 22WinEventLog:SysmonEventCode=11
Linux Analytic 1512
Processes (tar, curl, python scripts) accessing large file sets and initiating outbound HTTPS POST requests with payload sizes inconsistent with baseline activity. Defender perspective: detect abnormal sequence of file archival followed by encrypted uploads to external web services.
auditd:EXECVEcurl or wget with POST/PUT optionsauditd:SYSCALLopen/read of sensitive directories (/etc, /home/*)NSM:Flowsustained outbound HTTPS sessions with high data volume
macOS Analytic 1513
Office apps or scripts writing files followed by xattr manipulation (to evade quarantine) and subsequent HTTPS uploads. Defender perspective: anomalous file modification + outbound TLS traffic originating from non-networking apps (Word, Excel, Preview).
macos:unifiedlogexecution of Office binaries with network activitymacos:unifiedlogread/write of user documents prior to uploadmacos:unifiedlogoutbound TLS connections to cloud storage providers
SaaS Analytic 1514
Abnormal API calls from user accounts invoking file upload endpoints outside normal baselines (M365, Google Drive, Box). Defender perspective: monitor unified audit logs for elevated frequency of Upload, Create, or Copy operations from compromised accounts.
m365:unifiedFileUploaded or FileCopied eventssaas:boxAPI calls exceeding baseline thresholds
ESXi Analytic 1515
ESXi guest OS or management interface processes establishing unexpected external HTTPS connections. Defender perspective: monitor vmx or hostd processes making outbound web requests with significant data transfer.
esxi:vmkernelnetwork session initiation with external HTTPS servicesesxi:hostdfile copy or datastore upload via HTTPS
Sub-techniques with coverage
Counted in the 173 above — a rule tagged a sub-technique covers this technique too.
Emerging Threats Open
61 rules| Detection | Severity | Format |
|---|---|---|
| ET MALWARE OtterCookie File Exfiltration M1 | Critical | Suricata |
| ET HUNTING Request for Webshell in .well-known directory | High | Suricata |
| ET MALWARE Observed TransferLoader Domain (baza .com) in TLS SNI | High | Suricata |
| ET MALWARE Observed TransferLoader Domain (mainstomp .cloud) in TLS SNI | High | Suricata |
| ET MALWARE Observed TransferLoader Domain (sharemoc .space) in TLS SNI | High | Suricata |
| ET MALWARE Observed TransferLoader Domain (temptransfer .live) in TLS SNI | High | Suricata |
| ET MALWARE Observed Win32/Ailurophile Stealer Domain (manestvli .shop) in TLS SNI | High | Suricata |
| ET MALWARE Screenshot Exfiltration via Discord Webhook (POST) | High | Suricata |
| ET MALWARE Specter Insight Beacon CnC Checkin M1 | High | Suricata |
| ET MALWARE SvcStealer CNC Tasking Checkin | High | Suricata |
+ 51 more from Emerging Threats Open → showing the 10 highest-severity
SigmaHQ/sigma
28 rules| Detection | Severity | Format |
|---|---|---|
| APT40 Dropbox Tool User Agent | High | Sigma |
| Communication To Ngrok Tunneling Service Initiated | High | Sigma |
| Communication To Ngrok Tunneling Service - Linux | High | Sigma |
| Curl File Upload To File Sharing Websites | High | Sigma |
| DNS Query for Anonfiles.com Domain - DNS Client | High | Sigma |
| DNS Query for Anonfiles.com Domain - Sysmon | High | Sigma |
| Monero Crypto Coin Mining Pool Lookup | High | Sigma |
| Process Initiated Network Connection To Ngrok Domain | High | Sigma |
| PUA - Rclone Execution | High | Sigma |
| PUA - Restic Backup Tool Execution | High | Sigma |
+ 18 more from SigmaHQ/sigma → showing the 10 highest-severity
elastic/detection-rules
24 rules| Detection | Severity | Format |
|---|---|---|
| AWS DynamoDB Table Exported to S3 | High | Elastic TOML |
| AWS RDS Snapshot Export | High | Elastic TOML |
| AWS S3 Bucket Replicated to Another Account | High | Elastic TOML |
| AWS SNS Topic Message Publish by Rare User | High | Elastic TOML |
| Network Connection to OAST Domain via Script Interpreter | High | Elastic TOML |
| AWS EC2 Export Task | Medium | Elastic TOML |
| Azure Storage Blob Retrieval via AzCopy | Medium | Elastic TOML |
| GitHub Exfiltration via High Number of Repository Clones by User | Medium | Elastic TOML |
| High Number of Closed Pull Requests by User | Medium | Elastic TOML |
| High Number of Protected Branch Force Pushes by User | Medium | Elastic TOML |
+ 14 more from elastic/detection-rules → showing the 10 highest-severity
panther-labs/panther-analysis
23 rules| Detection | Severity | Format |
|---|---|---|
| Slack Enterprise Key Management Unenrolled | Critical | Panther Python |
| Slack Microsoft Intune Mobile Device Management Disabled | Critical | Panther Python |
| Azure Storage Account Public Network Access Enabled | High | Panther Python |
| Azure VM Disk SAS URI Generated | High | Panther Python |
| Box Shield Detected Anomalous Download Activity | High | Panther Python |
| CodeBuild Project made Public | High | Panther Python |
| DNS request to denylisted domain | High | Panther Python |
| GitHub Repository Visibility Change | High | Panther Python |
| Slack Private Channel Made Public | High | Panther Python |
| Anthropic Artifact Shared Publicly | Medium | Panther Python |
+ 13 more from panther-labs/panther-analysis → showing the 10 highest-severity
splunk/security_content
16 rules| Detection | Severity | Format |
|---|---|---|
| Cisco NVM - Rclone Execution With Network Activity | Undefined | SPL |
| Cisco Secure Firewall - Connection to File Sharing Domain | Undefined | SPL |
| Cisco Secure Firewall - Potential Data Exfiltration | Undefined | SPL |
| Cisco TFTP Server Configuration for Data Exfiltration | Undefined | SPL |
| Gsuite Drive Share In External Email | Undefined | SPL |
| High Volume of Bytes Out to Url | Undefined | SPL |
| Linux Gdrive Binary Activity | Undefined | SPL |
| LOLBAS With Network Traffic | Undefined | SPL |
| O365 DLP Rule Triggered | Undefined | SPL |
| O365 Email Access By Security Administrator | Undefined | SPL |
+ 6 more from splunk/security_content → showing the 10 highest-severity
Azure/Azure-Sentinel
7 rules| Detection | Severity | Format |
|---|---|---|
| CreepyDrive request URL sequence | High | KQL |
| CreepyDrive URLs | High | KQL |
| First-Time Network Connection by Unusual Process | High | KQL |
| Suspect Mailbox Export on IIS/OWA | Low | KQL |
| Cross-service Azure Data Explorer queries | Undefined | KQL |
| Discord download invoked from cmd line (ASIM Version) | Undefined | KQL |
| Gentlemen Ransomware C2 domain connection | Undefined | KQL |
chronicle/detection-rules
7 rules| Detection | Severity | Format |
|---|---|---|
| gcp_bigquery_results_downloaded_from_multiple_tables | High | YARA-L |
| google_workspace_file_shared_from_google_drive_to_free_email_domain | High | YARA-L |
| google_workspace_multiple_files_copied_from_google_drive | High | YARA-L |
| google_workspace_multiple_files_downloaded_from_google_drive | High | YARA-L |
| google_workspace_multiple_files_sent_as_email_attachment_from_google_drive | High | YARA-L |
| google_workspace_suspicious_login_and_google_drive_file_download | High | YARA-L |
| google_workspace_suspicious_login_and_google_drive_file_share | High | YARA-L |
socfortress/Wazuh-Rules
5 rules| Detection | Severity | Format |
|---|---|---|
| Sysmon - Event 1: Process creation · Pastebin Exfiltration via PowerShell (T1567.002) | High | Wazuh XML |
| Sysmon - Event 1: Process creation · Rclone Cloud Exfiltration (T1567.002) | High | Wazuh XML |
| operation. · office_365.Operation = ExportForm | Low | Wazuh XML |
| operation. · office_365.Operation = PreviewForm | Low | Wazuh XML |
| operation. · office_365.Operation = ViewRuntimeForm | Low | Wazuh XML |
Wazuh Core Ruleset
2 rules| Detection | Severity | Format |
|---|---|---|
| A connection to cloud resource was started by · win.eventdata.commandLine = (?i)(live|outlook|google|drive|microsoft|dropbox) | High | Wazuh XML |
| A net.exe connection to a remote resource was started by · win.eventdata.commandLine = (?i)use\s | Low | Wazuh XML |