T1041Techniqueexfiltrationagent-callable

T1041Exfiltration Over C2 Channel

Platforms: Linux · macOS · Windows

ATT&CK version: 14.1

What it is

Adversaries may steal data by exfiltrating it over an existing command and control channel. Stolen data is encoded into the normal communications channel using the same protocol as command and control communications.

ATT&CK tactics· 1

Exfiltration

References

  1. https://attack.mitre.org/techniques/T1041
  2. https://arxiv.org/ftp/arxiv/papers/1408/1408.1136.pdf
Sourced from MITRE ATT&CK Enterprise v14.1. Curated and contextualized for EU compliance use cases by Adam Lundqvist, Founder at SQUR.
T1041: Exfiltration Over C2 Channel | SQUR Knowledge Base