{"id":"T1567.004","name":"Exfiltration Over Webhook","url":"https://attack.mitre.org/techniques/T1567/004","tactics":["exfiltration"],"platforms":["ESXi","Linux","macOS","Office Suite","SaaS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0153","stix_id":"x-mitre-detection-strategy--dcc26ef4-3ecd-4b37-b4b4-66faee084352","name":"Detection Strategy for Exfiltration Over Webhook","url":"https://attack.mitre.org/detectionstrategies/DET0153","analytics":[{"id":"AN0436","stix_id":"x-mitre-analytic--98bd8e15-68ea-43a3-982b-66fcd1142c9a","name":"Analytic 0436","description":"Unusual processes (e.g., powershell.exe, wscript.exe, mshta.exe) posting data to webhook endpoints (Discord, Slack, webhook.site) using HTTP POST/PUT requests. Defender perspective: suspicious process lineage followed by outbound HTTPS traffic to webhook domains.","url":"https://attack.mitre.org/detectionstrategies/DET0153#AN0436","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=3, 22","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Security","channel":"EventCode=4663, 4670, 4656","data_component":"DC0055","data_component_name":"File Access","log_source_slug":"wineventlog-security"}],"mutable_elements":[{"field":"WebhookDomains","description":"Domains to monitor such as discord.com/api/webhooks, slack.com/api, webhook.site."},{"field":"UploadSizeThreshold","description":"Threshold for abnormal data sent via webhook requests."},{"field":"ApprovedApps","description":"List of approved business apps using webhooks to reduce noise."}],"live":true,"detection_strategies":["DET0153"],"techniques":["T1567.004"]},{"id":"AN0437","stix_id":"x-mitre-analytic--053dd0c5-9746-46ea-bdeb-b385bf5cbbf8","name":"Analytic 0437","description":"Processes such as curl, wget, or custom scripts initiating POST requests to webhook endpoints with encoded or bulk data. Defender perspective: abnormal chaining of file compression or access followed by outbound data to webhook URLs.","url":"https://attack.mitre.org/detectionstrategies/DET0153#AN0437","platforms":["Linux"],"log_source_references":[{"name":"auditd:EXECVE","channel":"curl -X POST, wget --post-data","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"auditd-execve"},{"name":"auditd:SYSCALL","channel":"read/open of sensitive files","data_component":"DC0055","data_component_name":"File Access","log_source_slug":"auditd-syscall"},{"name":"NSM:Flow","channel":"large HTTPS POST requests to webhook endpoints","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"AllowedTools","description":"Expected command-line utilities allowed to interact with webhooks in enterprise environments."},{"field":"TimeWindow","description":"Expected timeframe for legitimate webhook traffic (e.g., CI/CD deployments)."}],"live":true,"detection_strategies":["DET0153"],"techniques":["T1567.004"]},{"id":"AN0438","stix_id":"x-mitre-analytic--d7f9b07f-401c-4685-a014-6a824f95f866","name":"Analytic 0438","description":"Unexpected apps or scripts (osascript, curl, Automator workflows) exfiltrating data via webhooks. Defender perspective: correlation of clipboard/file read operations followed by HTTPS POST traffic to webhook services.","url":"https://attack.mitre.org/detectionstrategies/DET0153#AN0438","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"execution of osascript, curl, or unexpected automation","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"file read of sensitive directories","data_component":"DC0055","data_component_name":"File Access","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"HTTPS POST to known webhook URLs","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"WebhookEndpoints","description":"Webhook URLs monitored for exfiltration."},{"field":"EntropyThreshold","description":"High entropy payloads may indicate encoded/encrypted exfiltration."}],"live":true,"detection_strategies":["DET0153"],"techniques":["T1567.004"]},{"id":"AN0439","stix_id":"x-mitre-analytic--37166782-8770-4812-b70c-27f3c705489b","name":"Analytic 0439","description":"VMware services or management daemons generating HTTP POST requests to webhook endpoints, chained with unusual datastore or log access. Defender perspective: exfiltration from VM logs or disk images over webhook URLs.","url":"https://attack.mitre.org/detectionstrategies/DET0153#AN0439","platforms":["ESXi"],"log_source_references":[{"name":"esxi:hostd","channel":"datastore file access","data_component":"DC0055","data_component_name":"File Access","log_source_slug":"esxi-hostd"},{"name":"esxi:vmkernel","channel":"HTTPS POST connections to webhook endpoints","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"esxi-vmkernel"}],"mutable_elements":[{"field":"DatastoreExfilThreshold","description":"Minimum data volume to flag exfiltration attempts from VM files."},{"field":"ApprovedIntegrations","description":"Whitelisted CI/CD or automation webhooks tied to vSphere/ESXi."}],"live":true,"detection_strategies":["DET0153"],"techniques":["T1567.004"]},{"id":"AN0440","stix_id":"x-mitre-analytic--4b72b349-f810-4e34-9185-b5550147147e","name":"Analytic 0440","description":"Suspicious SaaS tenant activity involving webhook configurations pointing to external or untrusted domains. Defender perspective: repeated automated exports or suspicious webhook endpoint registrations.","url":"https://attack.mitre.org/detectionstrategies/DET0153#AN0440","platforms":["SaaS"],"log_source_references":[{"name":"m365:unified","channel":"Set-Mailbox, Add-InboxRule, RegisterWebhook","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"m365-unified"},{"name":"saas:api","channel":"Webhook registrations or repeated POST activity","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"saas-api"}],"mutable_elements":[{"field":"WebhookRegistrations","description":"Monitor new webhook creation events in SaaS environments."},{"field":"ExternalDomains","description":"Flag webhooks pointing to domains not owned by the enterprise."}],"live":true,"detection_strategies":["DET0153"],"techniques":["T1567.004"]}],"live":true,"version":"1.0","techniques":["T1567.004"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}