{"id":"T1567.002","name":"Exfiltration to Cloud Storage","url":"https://attack.mitre.org/techniques/T1567/002","tactics":["exfiltration"],"platforms":["ESXi","Linux","macOS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0570","stix_id":"x-mitre-detection-strategy--c8895822-a3d1-41eb-952f-c67b4673eee2","name":"Detection Strategy for Exfiltration to Cloud Storage","url":"https://attack.mitre.org/detectionstrategies/DET0570","analytics":[{"id":"AN1571","stix_id":"x-mitre-analytic--a74c34c2-f4bf-4bd0-9f23-7c04c45b93ca","name":"Analytic 1571","description":"Unusual processes (e.g., powershell.exe, excel.exe) accessing large local files and subsequently initiating HTTPS POST requests to domains associated with cloud storage services (e.g., dropbox.com, drive.google.com, box.com). Defender perspective: correlation between file reads in sensitive directories and high outbound traffic volume to known storage APIs.","url":"https://attack.mitre.org/detectionstrategies/DET0570#AN1571","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4663, 4670, 4656","data_component":"DC0055","data_component_name":"File Access","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Sysmon","channel":"EventCode=3, 22","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"CloudStorageDomains","description":"List of monitored domains for cloud services (dropbox.com, drive.google.com, onedrive.live.com)."},{"field":"ExfilVolumeThreshold","description":"Data volume threshold (e.g., >10MB in single session) used to flag abnormal transfers."},{"field":"UserContext","description":"User accounts permitted to use sanctioned cloud services versus unexpected accounts."}],"live":true,"detection_strategies":["DET0570"],"techniques":["T1567.002"]},{"id":"AN1572","stix_id":"x-mitre-analytic--5012d2b2-bd36-431c-91d3-4c10b7d3a9d6","name":"Analytic 1572","description":"Processes such as curl, wget, rclone, or custom scripts executing uploads to cloud storage endpoints. Defender perspective: detect chained events where tar/gzip is executed to compress files followed by HTTPS PUT/POST requests to known storage services.","url":"https://attack.mitre.org/detectionstrategies/DET0570#AN1572","platforms":["Linux"],"log_source_references":[{"name":"auditd:EXECVE","channel":"curl -T, rclone copy","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"auditd-execve"},{"name":"auditd:SYSCALL","channel":"read/open of sensitive file directories","data_component":"DC0055","data_component_name":"File Access","log_source_slug":"auditd-syscall"},{"name":"NSM:Flow","channel":"large HTTPS outbound uploads","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"AllowedTools","description":"Known tools used legitimately for backups (rclone, gsutil). Deviations raise suspicion."},{"field":"WorkHours","description":"Baseline normal data transfer hours to reduce false positives."}],"live":true,"detection_strategies":["DET0570"],"techniques":["T1567.002"]},{"id":"AN1573","stix_id":"x-mitre-analytic--535e9bc8-b033-4aee-88e1-bd48699b7856","name":"Analytic 1573","description":"Applications or scripts invoking cloud storage APIs (Dropbox sync, iCloud, Google Drive client) in unexpected contexts. Defender perspective: detect sensitive file reads by non-standard applications followed by unusual encrypted uploads to external cloud storage domains.","url":"https://attack.mitre.org/detectionstrategies/DET0570#AN1573","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"execution of curl, rclone, or Office apps invoking network sessions","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"file read of sensitive directories","data_component":"DC0055","data_component_name":"File Access","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"outbound HTTPS connections to cloud storage APIs","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"WatchedApps","description":"Track processes that normally should not upload data (e.g., Preview, Calculator)."},{"field":"EntropyThreshold","description":"High-entropy file uploads may indicate encrypted payloads designed for exfiltration."}],"live":true,"detection_strategies":["DET0570"],"techniques":["T1567.002"]},{"id":"AN1574","stix_id":"x-mitre-analytic--682f84f1-5571-4d41-b071-53c8f72a88f1","name":"Analytic 1574","description":"Unusual ESXi processes (vmx, hostd) reading datastore files and generating outbound HTTPS traffic toward external cloud storage endpoints. Defender perspective: anomalous datastore activity followed by network transfers to Dropbox, AWS S3, or other storage services.","url":"https://attack.mitre.org/detectionstrategies/DET0570#AN1574","platforms":["ESXi"],"log_source_references":[{"name":"esxi:hostd","channel":"datastore file access","data_component":"DC0055","data_component_name":"File Access","log_source_slug":"esxi-hostd"},{"name":"esxi:vmkernel","channel":"network flows to external cloud services","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"esxi-vmkernel"}],"mutable_elements":[{"field":"DatastoreTransferThreshold","description":"Threshold for outbound data exfiltration from ESXi datastore files."},{"field":"ApprovedStorageServices","description":"Whitelist of sanctioned storage providers used by admins for backup operations."}],"live":true,"detection_strategies":["DET0570"],"techniques":["T1567.002"]}],"live":true,"version":"1.0","techniques":["T1567.002"]}],"sigma_rules":[{"id":"065cceea-77ec-4030-9052-fc0affea7110","title":"DNS Query for Anonfiles.com Domain - Sysmon","author":"pH-T (Nextron Systems)","status":"test","level":"high","date":"2022-07-15","modified":"2023-01-16","description":"Detects DNS queries for \"anonfiles.com\", which is an anonymous file upload platform often used for malicious purposes","references":["https://www.trendmicro.com/vinfo/us/security/news/ransomware-spotlight/ransomware-spotlight-blackbyte"],"logsource":{"product":"windows","category":"dns_query"},"tags":["attack.exfiltration","attack.t1567.002"],"path":"rules/windows/dns_query/dns_query_win_anonymfiles_com.yml","techniques":["T1567.002"],"cves":[]},{"id":"090ffaad-c01a-4879-850c-6d57da98452d","title":"DNS Query To Ufile.io - DNS Client","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"low","date":"2023-01-16","modified":"2023-09-18","description":"Detects DNS queries to \"ufile.io\", which was seen abused by malware and threat actors as a method for data exfiltration","references":["https://thedfirreport.com/2021/12/13/diavol-ransomware/"],"logsource":{"product":"windows","service":"dns-client"},"tags":["attack.exfiltration","attack.t1567.002"],"path":"rules/windows/builtin/dns_client/win_dns_client_ufile_io.yml","techniques":["T1567.002"],"cves":[]},{"id":"1cbbeaaf-3c8c-4e4c-9d72-49485b6a176b","title":"DNS Query To Ufile.io","author":"yatinwad, TheDFIRReport","status":"test","level":"low","date":"2022-06-23","modified":"2023-09-18","description":"Detects DNS queries to \"ufile.io\", which was seen abused by malware and threat actors as a method for data exfiltration","references":["https://thedfirreport.com/2021/12/13/diavol-ransomware/"],"logsource":{"product":"windows","category":"dns_query"},"tags":["attack.exfiltration","attack.t1567.002"],"path":"rules/windows/dns_query/dns_query_win_ufile_io_query.yml","techniques":["T1567.002"],"cves":[]},{"id":"25eabf56-22f0-4915-a1ed-056b8dae0a68","title":"Suspicious Dropbox API Usage","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2022-04-20","modified":null,"description":"Detects an executable that isn't dropbox but communicates with the Dropbox API","references":["https://app.any.run/tasks/7e906adc-9d11-447f-8641-5f40375ecebb","https://www.zscaler.com/blogs/security-research/new-espionage-attack-molerats-apt-targeting-users-middle-east"],"logsource":{"product":"windows","category":"network_connection"},"tags":["attack.command-and-control","attack.exfiltration","attack.t1105","attack.t1567.002"],"path":"rules/windows/network_connection/net_connection_win_domain_dropbox_api.yml","techniques":["T1105","T1567.002"],"cves":[]},{"id":"29f171d7-aa47-42c7-9c7b-3c87938164d9","title":"DNS Query for Anonfiles.com Domain - DNS Client","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2023-01-16","modified":null,"description":"Detects DNS queries for anonfiles.com, which is an anonymous file upload platform often used for malicious purposes","references":["https://www.trendmicro.com/vinfo/us/security/news/ransomware-spotlight/ransomware-spotlight-blackbyte"],"logsource":{"product":"windows","service":"dns-client"},"tags":["attack.exfiltration","attack.t1567.002"],"path":"rules/windows/builtin/dns_client/win_dns_client_anonymfiles_com.yml","techniques":["T1567.002"],"cves":[]},{"id":"2c03648b-e081-41a5-b9fb-7d854a915091","title":"Rclone Activity via Proxy","author":"Janantha Marasinghe","status":"test","level":"medium","date":"2022-10-18","modified":null,"description":"Detects the use of rclone, a command-line program to manage files on cloud storage, via its default user-agent string","references":["https://rclone.org/","https://www.kroll.com/en/insights/publications/cyber/new-m365-business-email-compromise-attacks-with-rclone"],"logsource":{"category":"proxy"},"tags":["attack.exfiltration","attack.t1567.002"],"path":"rules/web/proxy_generic/proxy_ua_rclone.yml","techniques":["T1567.002"],"cves":[]},{"id":"34986307-b7f4-49be-92f3-e7a4d01ac5db","title":"Rclone Config File Creation","author":"Aaron Greetham (@beardofbinary) - NCC Group","status":"test","level":"medium","date":"2021-05-26","modified":"2023-05-09","description":"Detects Rclone config files being created","references":["https://research.nccgroup.com/2021/05/27/detecting-rclone-an-effective-tool-for-exfiltration/"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.exfiltration","attack.t1567.002"],"path":"rules/windows/file/file_event/file_event_win_rclone_config_files.yml","techniques":["T1567.002"],"cves":[]},{"id":"5ba715b6-71b7-44fd-8245-f66893e81b3d","title":"APT40 Dropbox Tool User Agent","author":"Thomas Patzke","status":"test","level":"high","date":"2019-11-12","modified":"2023-05-18","description":"Detects suspicious user agent string of APT40 Dropbox tool","references":["Internal research from Florian Roth"],"logsource":{"category":"proxy"},"tags":["attack.command-and-control","attack.t1071.001","attack.exfiltration","attack.t1567.002","detection.emerging-threats"],"path":"rules-emerging-threats/2019/TA/APT40/proxy_apt_apt40_dropbox_tool_ua.yml","techniques":["T1071.001","T1567.002"],"cves":[]},{"id":"613c03ba-0779-4a53-8a1f-47f914a4ded3","title":"DNS Query To MEGA Hosting Website","author":"Aaron Greetham (@beardofbinary) - NCC Group","status":"test","level":"medium","date":"2021-05-26","modified":"2023-09-18","description":"Detects DNS queries for subdomains related to MEGA sharing website","references":["https://research.nccgroup.com/2021/05/27/detecting-rclone-an-effective-tool-for-exfiltration/"],"logsource":{"product":"windows","category":"dns_query"},"tags":["attack.exfiltration","attack.t1567.002"],"path":"rules/windows/dns_query/dns_query_win_mega_nz.yml","techniques":["T1567.002"],"cves":[]},{"id":"66474410-b883-415f-9f8d-75345a0a66a6","title":"DNS Query To MEGA Hosting Website - DNS Client","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2023-01-16","modified":null,"description":"Detects DNS queries for subdomains related to MEGA sharing website","references":["https://research.nccgroup.com/2021/05/27/detecting-rclone-an-effective-tool-for-exfiltration/"],"logsource":{"product":"windows","service":"dns-client"},"tags":["attack.exfiltration","attack.t1567.002"],"path":"rules/windows/builtin/dns_client/win_dns_client_mega_nz.yml","techniques":["T1567.002"],"cves":[]},{"id":"6ddff2e8-ea1a-45d0-8938-93dfc1d67ae7","title":"PUA - Restic Backup Tool Execution","author":"Nounou Mbeiri, Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"high","date":"2025-10-17","modified":null,"description":"Detects the execution of the Restic backup tool, which can be used for data exfiltration.\nThreat actors may leverage Restic to back up and exfiltrate sensitive data to remote storage locations, including cloud services.\nIf not legitimately used in the enterprise environment, its presence may indicate malicious activity.\n","references":["https://thedfirreport.com/2024/09/30/nitrogen-campaign-drops-sliver-and-ends-with-blackcat-ransomware/#exfiltration","https://restic.net/","https://restic.readthedocs.io/en/stable/030_preparing_a_new_repo.html"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.exfiltration","attack.t1048","attack.t1567.002"],"path":"rules/windows/process_creation/proc_creation_win_pua_restic.yml","techniques":["T1048","T1567.002"],"cves":[]},{"id":"e328cc73-f92a-42fb-b3fa-7c2cffda981a","title":"Curl File Upload To File Sharing Websites","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"high","date":"2026-03-29","modified":null,"description":"Detects usage of curl to upload files to known file sharing domains, which may indicate data exfiltration.","references":["https://unit42.paloaltonetworks.com/advanced-backdoor-squidoor/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.exfiltration","attack.t1567.002"],"path":"rules/windows/process_creation/proc_creation_win_curl_upload_file_sharing_websites.yml","techniques":["T1567.002"],"cves":[]},{"id":"e37db05d-d1f9-49c8-b464-cee1a4b11638","title":"PUA - Rclone Execution","author":"Bhabesh Raj, Sittikorn S, Aaron Greetham (@beardofbinary) - NCC Group","status":"test","level":"high","date":"2021-05-10","modified":"2023-03-05","description":"Detects execution of RClone utility for exfiltration as used by various ransomwares strains like REvil, Conti, FiveHands, etc","references":["https://research.nccgroup.com/2021/05/27/detecting-rclone-an-effective-tool-for-exfiltration/","https://thedfirreport.com/2021/03/29/sodinokibi-aka-revil-ransomware","https://us-cert.cisa.gov/ncas/analysis-reports/ar21-126a","https://labs.sentinelone.com/egregor-raas-continues-the-chaos-with-cobalt-strike-and-rclone","https://www.splunk.com/en_us/blog/security/darkside-ransomware-splunk-threat-update-and-detections.html"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.exfiltration","attack.t1567.002"],"path":"rules/windows/process_creation/proc_creation_win_pua_rclone_execution.yml","techniques":["T1567.002"],"cves":[]},{"id":"fdeebdf0-9f3f-4d08-84a6-4c4d13e39fe4","title":"Network Connection Initiated To Mega.nz","author":"Florian Roth (Nextron Systems)","status":"test","level":"low","date":"2021-12-06","modified":"2024-05-31","description":"Detects a network connection initiated by a binary to \"api.mega.co.nz\".\nAttackers were seen abusing file sharing websites similar to \"mega.nz\" in order to upload/download additional payloads.\n","references":["https://megatools.megous.com/","https://www.mandiant.com/resources/russian-targeting-gov-business"],"logsource":{"product":"windows","category":"network_connection"},"tags":["attack.exfiltration","attack.t1567.002"],"path":"rules/windows/network_connection/net_connection_win_domain_mega_nz.yml","techniques":["T1567.002"],"cves":[]}],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}