T1020Techniqueexfiltrationagent-callable

T1020Automated Exfiltration

Platforms: Linux · macOS · Network Devices · Windows

ATT&CK version: v19.1

What it is

Adversaries may exfiltrate data, such as sensitive documents, through the use of automated processing after being gathered during Collection.(Citation: ESET Gamaredon June 2020) When automated exfiltration is used, other exfiltration techniques likely apply as well to transfer the information out of the network, such as [Exfiltration Over C2 Channel](https://attack.mitre.org/techniques/T1041) and [Exfiltration Over Alternative Protocol](https://attack.mitre.org/techniques/T1048).

ATT&CK tactics· 1

Exfiltration

References

  1. https://attack.mitre.org/techniques/T1020
  2. https://www.welivesecurity.com/2020/06/11/gamaredon-group-grows-its-game/
Sourced from MITRE ATT&CK Enterprise v14.1. Curated and contextualized for EU compliance use cases by Adam Lundqvist, Founder at SQUR.
T1020: Automated Exfiltration | SQUR Knowledge Base