{"id":"T1011.001","name":"Exfiltration Over Bluetooth","url":"https://attack.mitre.org/techniques/T1011/001","tactics":["exfiltration"],"platforms":["Linux","macOS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0554","stix_id":"x-mitre-detection-strategy--267a6c25-8d34-47ae-8357-9ae173adaa13","name":"Detection of Bluetooth-Based Data Exfiltration","url":"https://attack.mitre.org/detectionstrategies/DET0554","analytics":[{"id":"AN1531","stix_id":"x-mitre-analytic--02fb4d83-d2db-4d49-acbc-85eff3b517d6","name":"Analytic 1531","description":"Detection of non-interactive or suspicious processes accessing Bluetooth interfaces and transmitting outbound traffic following file access or staging activity.","url":"https://attack.mitre.org/detectionstrategies/DET0554#AN1531","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:System","channel":"EventCode=8001","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"wineventlog-system"},{"name":"WinEventLog:Sysmon","channel":"EventCode=11","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"TimeWindow","description":"Defines how quickly a file access and Bluetooth activity must occur to be correlated."},{"field":"InterfaceType","description":"May focus on Bluetooth-specific interfaces or drivers like 'bthport.sys'."},{"field":"FileSizeThreshold","description":"Tune to trigger only on significant exfiltratable file reads."}],"live":true,"detection_strategies":["DET0554"],"techniques":["T1011.001"]},{"id":"AN1532","stix_id":"x-mitre-analytic--01588556-4b25-4418-b746-9bca0279be2c","name":"Analytic 1532","description":"Use of hcitool, bluetoothctl, or rfcomm to initialize Bluetooth connection paired with recent file reads by the same user or session.","url":"https://attack.mitre.org/detectionstrategies/DET0554#AN1532","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"None","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"auditd-syscall"},{"name":"linux:syslog","channel":"None","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"linux-syslog"},{"name":"linux:osquery","channel":"None","data_component":"DC0055","data_component_name":"File Access","log_source_slug":"linux-osquery"}],"mutable_elements":[{"field":"BluetoothUtility","description":"List of CLI tools to monitor (e.g., hcitool, rfcomm, obexftp)."},{"field":"SessionWindow","description":"Amount of time after interface config a file must be accessed to be linked."}],"live":true,"detection_strategies":["DET0554"],"techniques":["T1011.001"]},{"id":"AN1533","stix_id":"x-mitre-analytic--2f6dd4a5-b0cc-4c13-abb8-e2d747d591b2","name":"Analytic 1533","description":"Observation of `blueutil`/`networksetup` commands or low-level APIs toggling Bluetooth or initiating transfers, especially if paired with recent large file read activity by non-GUI processes.","url":"https://attack.mitre.org/detectionstrategies/DET0554#AN1533","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"None","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"macos-unifiedlog"},{"name":"macos:osquery","channel":"None","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"macos-osquery"},{"name":"macos:osquery","channel":"None","data_component":"DC0055","data_component_name":"File Access","log_source_slug":"macos-osquery"}],"mutable_elements":[{"field":"ProcessContext","description":"Limit to background processes or scripts with no GUI interaction."},{"field":"PayloadType","description":"Focus on specific sensitive file types (e.g., zip, docx, keychain db)."}],"live":true,"detection_strategies":["DET0554"],"techniques":["T1011.001"]}],"live":true,"version":"1.0","techniques":["T1011.001"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}