Cross-source coverage

T1567 / ATT&CK

Exfiltration Over Web Service

173 rules across 9 sources.

6 deprecated hidden · include

Showing atomic-IOC rules · back to the default

From MITRE ATT&CK 19.2

Adversaries may use an existing, legitimate external Web service to exfiltrate data rather than their primary command and control channel. Popular Web services acting as an exfiltration mechanism may give a significant amount of cover due to the likelihood that hosts within a network are already communicating with them prior to compromise. Firewall rules may also already exist to permit traffic to these services.

Web service providers also commonly use SSL/TLS encryption, giving adversaries an added level of protection.

Tactics
Exfiltration
Platforms
ESXi · Linux · macOS · Office Suite · SaaS · Windows
Telemetry
WinEventLog:SecurityWinEventLog:Sysmonauditd:EXECVEauditd:SYSCALLNSM:Flowmacos:unifiedlogm365:unifiedsaas:boxesxi:vmkernelesxi:hostd

How MITRE says to detect it DET0548

Detection Strategy for Exfiltration Over Web Service

Windows Analytic 1511

Processes that normally do not initiate network communications suddenly making outbound HTTPS connections with high outbound-to-inbound data ratios. Defender view: correlation between process creation logs (e.g., Word, Excel, PowerShell) and subsequent anomalous network traffic volumes toward common web services (Dropbox, Google Drive, OneDrive).

  • WinEventLog:Security EventCode=4688
  • WinEventLog:Sysmon EventCode=3, 22
  • WinEventLog:Sysmon EventCode=11

Linux Analytic 1512

Processes (tar, curl, python scripts) accessing large file sets and initiating outbound HTTPS POST requests with payload sizes inconsistent with baseline activity. Defender perspective: detect abnormal sequence of file archival followed by encrypted uploads to external web services.

  • auditd:EXECVE curl or wget with POST/PUT options
  • auditd:SYSCALL open/read of sensitive directories (/etc, /home/*)
  • NSM:Flow sustained outbound HTTPS sessions with high data volume

macOS Analytic 1513

Office apps or scripts writing files followed by xattr manipulation (to evade quarantine) and subsequent HTTPS uploads. Defender perspective: anomalous file modification + outbound TLS traffic originating from non-networking apps (Word, Excel, Preview).

  • macos:unifiedlog execution of Office binaries with network activity
  • macos:unifiedlog read/write of user documents prior to upload
  • macos:unifiedlog outbound TLS connections to cloud storage providers

SaaS Analytic 1514

Abnormal API calls from user accounts invoking file upload endpoints outside normal baselines (M365, Google Drive, Box). Defender perspective: monitor unified audit logs for elevated frequency of Upload, Create, or Copy operations from compromised accounts.

  • m365:unified FileUploaded or FileCopied events
  • saas:box API calls exceeding baseline thresholds

ESXi Analytic 1515

ESXi guest OS or management interface processes establishing unexpected external HTTPS connections. Defender perspective: monitor vmx or hostd processes making outbound web requests with significant data transfer.

  • esxi:vmkernel network session initiation with external HTTPS services
  • esxi:hostd file copy or datastore upload via HTTPS

Sub-techniques with coverage

Counted in the 173 above — a rule tagged a sub-technique covers this technique too.


Emerging Threats Open

61 rules
Detection Severity Format
ET MALWARE OtterCookie File Exfiltration M1 Critical Suricata
ET HUNTING Request for Webshell in .well-known directory High Suricata
ET MALWARE Observed TransferLoader Domain (baza .com) in TLS SNI High Suricata
ET MALWARE Observed TransferLoader Domain (mainstomp .cloud) in TLS SNI High Suricata
ET MALWARE Observed TransferLoader Domain (sharemoc .space) in TLS SNI High Suricata
ET MALWARE Observed TransferLoader Domain (temptransfer .live) in TLS SNI High Suricata
ET MALWARE Observed Win32/Ailurophile Stealer Domain (manestvli .shop) in TLS SNI High Suricata
ET MALWARE Screenshot Exfiltration via Discord Webhook (POST) High Suricata
ET MALWARE Specter Insight Beacon CnC Checkin M1 High Suricata
ET MALWARE SvcStealer CNC Tasking Checkin High Suricata

+ 51 more from Emerging Threats Open → showing the 10 highest-severity

SigmaHQ/sigma

28 rules
Detection Severity Format
APT40 Dropbox Tool User Agent High Sigma
Communication To Ngrok Tunneling Service Initiated High Sigma
Communication To Ngrok Tunneling Service - Linux High Sigma
Curl File Upload To File Sharing Websites High Sigma
DNS Query for Anonfiles.com Domain - DNS Client High Sigma
DNS Query for Anonfiles.com Domain - Sysmon High Sigma
Monero Crypto Coin Mining Pool Lookup High Sigma
Process Initiated Network Connection To Ngrok Domain High Sigma
PUA - Rclone Execution High Sigma
PUA - Restic Backup Tool Execution High Sigma

+ 18 more from SigmaHQ/sigma → showing the 10 highest-severity

elastic/detection-rules

24 rules
Detection Severity Format
AWS DynamoDB Table Exported to S3 High Elastic TOML
AWS RDS Snapshot Export High Elastic TOML
AWS S3 Bucket Replicated to Another Account High Elastic TOML
AWS SNS Topic Message Publish by Rare User High Elastic TOML
Network Connection to OAST Domain via Script Interpreter High Elastic TOML
AWS EC2 Export Task Medium Elastic TOML
Azure Storage Blob Retrieval via AzCopy Medium Elastic TOML
GitHub Exfiltration via High Number of Repository Clones by User Medium Elastic TOML
High Number of Closed Pull Requests by User Medium Elastic TOML
High Number of Protected Branch Force Pushes by User Medium Elastic TOML

+ 14 more from elastic/detection-rules → showing the 10 highest-severity

panther-labs/panther-analysis

23 rules
Detection Severity Format
Slack Enterprise Key Management Unenrolled Critical Panther Python
Slack Microsoft Intune Mobile Device Management Disabled Critical Panther Python
Azure Storage Account Public Network Access Enabled High Panther Python
Azure VM Disk SAS URI Generated High Panther Python
Box Shield Detected Anomalous Download Activity High Panther Python
CodeBuild Project made Public High Panther Python
DNS request to denylisted domain High Panther Python
GitHub Repository Visibility Change High Panther Python
Slack Private Channel Made Public High Panther Python
Anthropic Artifact Shared Publicly Medium Panther Python

+ 13 more from panther-labs/panther-analysis → showing the 10 highest-severity

splunk/security_content

16 rules
Detection Severity Format
Cisco NVM - Rclone Execution With Network Activity Undefined SPL
Cisco Secure Firewall - Connection to File Sharing Domain Undefined SPL
Cisco Secure Firewall - Potential Data Exfiltration Undefined SPL
Cisco TFTP Server Configuration for Data Exfiltration Undefined SPL
Gsuite Drive Share In External Email Undefined SPL
High Volume of Bytes Out to Url Undefined SPL
Linux Gdrive Binary Activity Undefined SPL
LOLBAS With Network Traffic Undefined SPL
O365 DLP Rule Triggered Undefined SPL
O365 Email Access By Security Administrator Undefined SPL

+ 6 more from splunk/security_content → showing the 10 highest-severity

Azure/Azure-Sentinel

7 rules
Detection Severity Format
CreepyDrive request URL sequence High KQL
CreepyDrive URLs High KQL
First-Time Network Connection by Unusual Process High KQL
Suspect Mailbox Export on IIS/OWA Low KQL
Cross-service Azure Data Explorer queries Undefined KQL
Discord download invoked from cmd line (ASIM Version) Undefined KQL
Gentlemen Ransomware C2 domain connection Undefined KQL

chronicle/detection-rules

7 rules
Detection Severity Format
gcp_bigquery_results_downloaded_from_multiple_tables High YARA-L
google_workspace_file_shared_from_google_drive_to_free_email_domain High YARA-L
google_workspace_multiple_files_copied_from_google_drive High YARA-L
google_workspace_multiple_files_downloaded_from_google_drive High YARA-L
google_workspace_multiple_files_sent_as_email_attachment_from_google_drive High YARA-L
google_workspace_suspicious_login_and_google_drive_file_download High YARA-L
google_workspace_suspicious_login_and_google_drive_file_share High YARA-L

socfortress/Wazuh-Rules

5 rules
Detection Severity Format
Sysmon - Event 1: Process creation · Pastebin Exfiltration via PowerShell (T1567.002) High Wazuh XML
Sysmon - Event 1: Process creation · Rclone Cloud Exfiltration (T1567.002) High Wazuh XML
operation. · office_365.Operation = ExportForm Low Wazuh XML
operation. · office_365.Operation = PreviewForm Low Wazuh XML
operation. · office_365.Operation = ViewRuntimeForm Low Wazuh XML

Wazuh Core Ruleset

2 rules
Detection Severity Format
A connection to cloud resource was started by · win.eventdata.commandLine = (?i)(live|outlook|google|drive|microsoft|dropbox) High Wazuh XML
A net.exe connection to a remote resource was started by · win.eventdata.commandLine = (?i)use\s Low Wazuh XML

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.