T1567.002SubTechniqueexfiltrationagent-callable

T1567.002Exfiltration to Cloud Storage

Sub-technique of T1567

Platforms: Linux · macOS · Windows

ATT&CK version: 14.1

What it is

Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel. Cloud storage services allow for the storage, edit, and retrieval of data from a remote cloud storage server over the Internet. Examples of cloud storage services include Dropbox and Google Docs. Exfiltration to these cloud storage services can provide a significant amount of cover to the adversary if hosts within the network are already communicating with the service.

ATT&CK tactics· 1

Exfiltration

References

  1. https://attack.mitre.org/techniques/T1567/002
Sourced from MITRE ATT&CK Enterprise v14.1. Curated and contextualized for EU compliance use cases by Adam Lundqvist, Founder at SQUR.