T1567Techniqueexfiltrationagent-callable

T1567Exfiltration Over Web Service

Platforms: Linux · macOS · Windows · Office 365 · SaaS · Google Workspace

ATT&CK version: 14.1

What it is

Adversaries may use an existing, legitimate external Web service to exfiltrate data rather than their primary command and control channel. Popular Web services acting as an exfiltration mechanism may give a significant amount of cover due to the likelihood that hosts within a network are already communicating with them prior to compromise. Firewall rules may also already exist to permit traffic to these services. Web service providers also commonly use SSL/TLS encryption, giving adversaries an added level of protection.

ATT&CK tactics· 1

Exfiltration

References

  1. https://attack.mitre.org/techniques/T1567
Sourced from MITRE ATT&CK Enterprise v14.1. Curated and contextualized for EU compliance use cases by Adam Lundqvist, Founder at SQUR.
T1567: Exfiltration Over Web Service | SQUR Knowledge Base