{"id":"T1567","name":"Exfiltration Over Web Service","url":"https://attack.mitre.org/techniques/T1567","tactics":["exfiltration"],"platforms":["ESXi","Linux","macOS","Office Suite","SaaS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0548","stix_id":"x-mitre-detection-strategy--1753ab98-4530-4284-9bc3-5d4813abfb9e","name":"Detection Strategy for Exfiltration Over Web Service","url":"https://attack.mitre.org/detectionstrategies/DET0548","analytics":[{"id":"AN1511","stix_id":"x-mitre-analytic--81b1e9a7-b6f4-4cca-b07a-3498ab4abd4a","name":"Analytic 1511","description":"Processes that normally do not initiate network communications suddenly making outbound HTTPS connections with high outbound-to-inbound data ratios. Defender view: correlation between process creation logs (e.g., Word, Excel, PowerShell) and subsequent anomalous network traffic volumes toward common web services (Dropbox, Google Drive, OneDrive).","url":"https://attack.mitre.org/detectionstrategies/DET0548#AN1511","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4688","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Sysmon","channel":"EventCode=3, 22","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=11","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"MonitoredServices","description":"List of legitimate web services to baseline (Dropbox, OneDrive, Google Drive)."},{"field":"ExfilVolumeThreshold","description":"Outbound data threshold for flagging unusual activity, tunable by environment."},{"field":"TimeWindow","description":"Aggregation period to calculate anomalies in outbound data volume."}],"live":true,"detection_strategies":["DET0548"],"techniques":["T1567"]},{"id":"AN1512","stix_id":"x-mitre-analytic--8a5a1b1e-336f-41af-8f30-2fa7e8e10fab","name":"Analytic 1512","description":"Processes (tar, curl, python scripts) accessing large file sets and initiating outbound HTTPS POST requests with payload sizes inconsistent with baseline activity. Defender perspective: detect abnormal sequence of file archival followed by encrypted uploads to external web services.","url":"https://attack.mitre.org/detectionstrategies/DET0548#AN1512","platforms":["Linux"],"log_source_references":[{"name":"auditd:EXECVE","channel":"curl or wget with POST/PUT options","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"auditd-execve"},{"name":"auditd:SYSCALL","channel":"open/read of sensitive directories (/etc, /home/*)","data_component":"DC0055","data_component_name":"File Access","log_source_slug":"auditd-syscall"},{"name":"NSM:Flow","channel":"sustained outbound HTTPS sessions with high data volume","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"MonitoredTools","description":"Suspicious command-line utilities used for exfiltration (curl, wget, python)."},{"field":"DataVolumeThreshold","description":"Bytes transferred threshold per session to flag unusual uploads."}],"live":true,"detection_strategies":["DET0548"],"techniques":["T1567"]},{"id":"AN1513","stix_id":"x-mitre-analytic--d49c13ed-df07-4bb3-a2dc-43411e5d402a","name":"Analytic 1513","description":"Office apps or scripts writing files followed by xattr manipulation (to evade quarantine) and subsequent HTTPS uploads. Defender perspective: anomalous file modification + outbound TLS traffic originating from non-networking apps (Word, Excel, Preview).","url":"https://attack.mitre.org/detectionstrategies/DET0548#AN1513","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"execution of Office binaries with network activity","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"read/write of user documents prior to upload","data_component":"DC0055","data_component_name":"File Access","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"outbound TLS connections to cloud storage providers","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"WatchedApplications","description":"Applications not expected to perform bulk data transfers (Office apps, Preview)."}],"live":true,"detection_strategies":["DET0548"],"techniques":["T1567"]},{"id":"AN1514","stix_id":"x-mitre-analytic--177bb119-93cc-4319-b9a7-e8d308d958c4","name":"Analytic 1514","description":"Abnormal API calls from user accounts invoking file upload endpoints outside normal baselines (M365, Google Drive, Box). Defender perspective: monitor unified audit logs for elevated frequency of Upload, Create, or Copy operations from compromised accounts.","url":"https://attack.mitre.org/detectionstrategies/DET0548#AN1514","platforms":["SaaS"],"log_source_references":[{"name":"m365:unified","channel":"FileUploaded or FileCopied events","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"m365-unified"},{"name":"saas:box","channel":"API calls exceeding baseline thresholds","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"saas-box"}],"mutable_elements":[{"field":"APICallThreshold","description":"Maximum number of API calls per user/session before triggering alert."},{"field":"UserBaselineProfiles","description":"Baseline normal data transfer patterns by user/role."}],"live":true,"detection_strategies":["DET0548"],"techniques":["T1567"]},{"id":"AN1515","stix_id":"x-mitre-analytic--f1f23910-7ecd-498b-92e8-7b5aa0d53ac8","name":"Analytic 1515","description":"ESXi guest OS or management interface processes establishing unexpected external HTTPS connections. Defender perspective: monitor vmx or hostd processes making outbound web requests with significant data transfer.","url":"https://attack.mitre.org/detectionstrategies/DET0548#AN1515","platforms":["ESXi"],"log_source_references":[{"name":"esxi:vmkernel","channel":"network session initiation with external HTTPS services","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"esxi-vmkernel"},{"name":"esxi:hostd","channel":"file copy or datastore upload via HTTPS","data_component":"DC0055","data_component_name":"File Access","log_source_slug":"esxi-hostd"}],"mutable_elements":[{"field":"DatastoreTransferThreshold","description":"Threshold for outbound transfers from ESXi datastores."}],"live":true,"detection_strategies":["DET0548"],"techniques":["T1567"]}],"live":true,"version":"1.0","techniques":["T1567"]}],"sigma_rules":[{"id":"00b90cc1-17ec-402c-96ad-3a8117d7a582","title":"Suspicious Curl File Upload - Linux","author":"Nasreddine Bencherchali (Nextron Systems), Cedric MAURUGEON (Update)","status":"test","level":"medium","date":"2022-09-15","modified":"2023-05-02","description":"Detects a suspicious curl process start the adds a file to a web request","references":["https://twitter.com/d1r4c/status/1279042657508081664","https://medium.com/@petehouston/upload-files-with-curl-93064dcccc76","https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1105/T1105.md#atomic-test-19---curl-upload-file","https://curl.se/docs/manpage.html","https://www.trendmicro.com/en_us/research/22/i/how-malicious-actors-abuse-native-linux-tools-in-their-attacks.html"],"logsource":{"product":"linux","category":"process_creation"},"tags":["attack.exfiltration","attack.command-and-control","attack.t1567","attack.t1105"],"path":"rules/linux/process_creation/proc_creation_lnx_susp_curl_fileupload.yml","techniques":["T1567","T1105"],"cves":[]},{"id":"00bca14a-df4e-4649-9054-3f2aa676bc04","title":"Potential Data Exfiltration Via Curl.EXE","author":"Florian Roth (Nextron Systems), Cedric MAURUGEON (Update)","status":"test","level":"medium","date":"2020-07-03","modified":"2023-05-02","description":"Detects the execution of the \"curl\" process with \"upload\" flags. Which might indicate potential data exfiltration","references":["https://twitter.com/d1r4c/status/1279042657508081664","https://medium.com/@petehouston/upload-files-with-curl-93064dcccc76","https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1105/T1105.md#atomic-test-19---curl-upload-file","https://curl.se/docs/manpage.html"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.exfiltration","attack.command-and-control","attack.t1567","attack.t1105","detection.threat-hunting"],"path":"rules-threat-hunting/windows/process_creation/proc_creation_win_curl_fileupload.yml","techniques":["T1567","T1105"],"cves":[]},{"id":"18249279-932f-45e2-b37a-8925f2597670","title":"Process Initiated Network Connection To Ngrok Domain","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2022-07-16","modified":"2025-07-30","description":"Detects an executable initiating a network connection to \"ngrok\" domains.\nAttackers were seen using this \"ngrok\" in order to store their second stage payloads and malware.\nWhile communication with such domains can be legitimate, often times is a sign of either data exfiltration by malicious actors or additional download.\n","references":["https://ngrok.com/","https://ngrok.com/blog-post/new-ngrok-domains","https://www.virustotal.com/gui/file/cca0c1182ac114b44dc52dd2058fcd38611c20bb6b5ad84710681d38212f835a/","https://www.rnbo.gov.ua/files/2023_YEAR/CYBERCENTER/november/APT29%20attacks%20Embassies%20using%20CVE-2023-38831%20-%20report%20en.pdf"],"logsource":{"product":"windows","category":"network_connection"},"tags":["attack.exfiltration","attack.command-and-control","attack.t1567","attack.t1572","attack.t1102"],"path":"rules/windows/network_connection/net_connection_win_domain_ngrok.yml","techniques":["T1567","T1572","T1102"],"cves":[]},{"id":"19bf6fdb-7721-4f3d-867f-53467f6a5db6","title":"Communication To Ngrok Tunneling Service - Linux","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2022-11-03","modified":null,"description":"Detects an executable accessing an ngrok tunneling endpoint, which could be a sign of forbidden exfiltration of data exfiltration by malicious actors","references":["https://twitter.com/hakluke/status/1587733971814977537/photo/1","https://ngrok.com/docs/secure-tunnels/tunnels/ssh-reverse-tunnel-agent"],"logsource":{"product":"linux","category":"network_connection"},"tags":["attack.exfiltration","attack.command-and-control","attack.t1567","attack.t1568.002","attack.t1572","attack.t1090","attack.t1102","attack.s0508"],"path":"rules/linux/network_connection/net_connection_lnx_ngrok_tunnel.yml","techniques":["T1567","T1568.002","T1572","T1090","T1102"],"cves":[]},{"id":"1d08ac94-400d-4469-a82f-daee9a908849","title":"Communication To Ngrok Tunneling Service Initiated","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2022-11-03","modified":"2024-02-02","description":"Detects an executable initiating a network connection to \"ngrok\" tunneling domains.\nAttackers were seen using this \"ngrok\" in order to store their second stage payloads and malware.\nWhile communication with such domains can be legitimate, often times is a sign of either data exfiltration by malicious actors or additional download.\n","references":["https://twitter.com/hakluke/status/1587733971814977537/photo/1","https://ngrok.com/docs/secure-tunnels/tunnels/ssh-reverse-tunnel-agent"],"logsource":{"product":"windows","category":"network_connection"},"tags":["attack.exfiltration","attack.command-and-control","attack.t1567","attack.t1568.002","attack.t1572","attack.t1090","attack.t1102","attack.s0508"],"path":"rules/windows/network_connection/net_connection_win_domain_ngrok_tunnel.yml","techniques":["T1567","T1568.002","T1572","T1090","T1102"],"cves":[]},{"id":"1f0f6176-6482-4027-b151-00071af39d7e","title":"Arbitrary File Download Via ConfigSecurityPolicy.EXE","author":"frack113","status":"test","level":"medium","date":"2021-11-26","modified":"2022-05-16","description":"Detects the execution of \"ConfigSecurityPolicy.EXE\", a binary part of Windows Defender used to manage settings in Windows Defender.\nUsers can configure different pilot collections for each of the co-management workloads.\nIt can be abused by attackers in order to upload or download files.\n","references":["https://lolbas-project.github.io/lolbas/Binaries/ConfigSecurityPolicy/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.exfiltration","attack.t1567"],"path":"rules/windows/process_creation/proc_creation_win_configsecuritypolicy_download_file.yml","techniques":["T1567"],"cves":[]},{"id":"4b657234-038e-4ad5-997c-4be42340bce4","title":"Network Connection Initiated To Visual Studio Code Tunnels Domain","author":"Kamran Saifullah","status":"test","level":"medium","date":"2023-11-20","modified":null,"description":"Detects network connections to Visual Studio Code tunnel domains initiated by a process on a system. Attackers can abuse that feature to establish a reverse shell or persistence on a machine.\n","references":["https://ipfyx.fr/post/visual-studio-code-tunnel/","https://badoption.eu/blog/2023/01/31/code_c2.html","https://cydefops.com/vscode-data-exfiltration"],"logsource":{"product":"windows","category":"network_connection"},"tags":["attack.exfiltration","attack.command-and-control","attack.t1567","attack.t1572"],"path":"rules/windows/network_connection/net_connection_win_domain_vscode_tunnel_connection.yml","techniques":["T1567","T1572"],"cves":[]},{"id":"7cd1dcdc-6edf-4896-86dc-d1f19ad64903","title":"Network Connection Initiated To Cloudflared Tunnels Domains","author":"Kamran Saifullah, Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2024-05-27","modified":null,"description":"Detects network connections to Cloudflared tunnels domains initiated by a process on the system.\nAttackers can abuse that feature to establish a reverse shell or persistence on a machine.\n","references":["https://defr0ggy.github.io/research/Abusing-Cloudflared-A-Proxy-Service-To-Host-Share-Applications/","https://www.guidepointsecurity.com/blog/tunnel-vision-cloudflared-abused-in-the-wild/","Internal Research"],"logsource":{"product":"windows","category":"network_connection"},"tags":["attack.exfiltration","attack.command-and-control","attack.t1567","attack.t1572"],"path":"rules/windows/network_connection/net_connection_win_domain_cloudflared_communication.yml","techniques":["T1567","T1572"],"cves":[]},{"id":"9e02c8ec-02b9-43e8-81eb-34a475ba7965","title":"Network Connection Initiated To BTunnels Domains","author":"Kamran Saifullah","status":"test","level":"medium","date":"2024-09-13","modified":null,"description":"Detects network connections to BTunnels domains initiated by a process on the system.\nAttackers can abuse that feature to establish a reverse shell or persistence on a machine.\n","references":["https://defr0ggy.github.io/research/Utilizing-BTunnel-For-Data-Exfiltration/"],"logsource":{"product":"windows","category":"network_connection"},"tags":["attack.exfiltration","attack.command-and-control","attack.t1567","attack.t1572"],"path":"rules/windows/network_connection/net_connection_win_domain_btunnels.yml","techniques":["T1567","T1572"],"cves":[]},{"id":"b593fd50-7335-4682-a36c-4edcb68e4641","title":"Monero Crypto Coin Mining Pool Lookup","author":"Florian Roth (Nextron Systems)","status":"stable","level":"high","date":"2021-10-24","modified":null,"description":"Detects suspicious DNS queries to Monero mining pools","references":["https://www.nextron-systems.com/2021/10/24/monero-mining-pool-fqdns/"],"logsource":{"category":"dns"},"tags":["attack.impact","attack.t1496","attack.exfiltration","attack.t1567"],"path":"rules/network/dns/net_dns_pua_cryptocoin_mining_xmr.yml","techniques":["T1496","T1567"],"cves":[]},{"id":"c3dbbc9f-ef1d-470a-a90a-d343448d5875","title":"Suspicious Non-Browser Network Communication With Telegram API","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2023-05-19","modified":null,"description":"Detects an a non-browser process interacting with the Telegram API which could indicate use of a covert C2","references":["https://www.ncsc.gov.uk/static-assets/documents/malware-analysis-reports/small-sieve/NCSC-MAR-Small-Sieve.pdf"],"logsource":{"product":"windows","category":"network_connection"},"tags":["attack.command-and-control","attack.exfiltration","attack.t1102","attack.t1567","attack.t1105"],"path":"rules/windows/network_connection/net_connection_win_domain_telegram_api_non_browser_access.yml","techniques":["T1102","T1567","T1105"],"cves":[]},{"id":"e290b10b-1023-4452-a4a9-eb31a9013b3a","title":"LOLBAS Data Exfiltration by DataSvcUtil.exe","author":"Ialle Teixeira @teixeira0xfffff, Austin Songer @austinsonger","status":"test","level":"medium","date":"2021-09-30","modified":"2022-05-16","description":"Detects when a user performs data exfiltration by using DataSvcUtil.exe","references":["https://gist.github.com/teixeira0xfffff/837e5bfed0d1b0a29a7cb1e5dbdd9ca6","https://learn.microsoft.com/en-us/previous-versions/dotnet/framework/data/wcf/wcf-data-service-client-utility-datasvcutil-exe","https://learn.microsoft.com/en-us/previous-versions/dotnet/framework/data/wcf/generating-the-data-service-client-library-wcf-data-services","https://learn.microsoft.com/en-us/previous-versions/dotnet/framework/data/wcf/how-to-add-a-data-service-reference-wcf-data-services","https://lolbas-project.github.io/lolbas/Binaries/DataSvcUtil/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.exfiltration","attack.t1567"],"path":"rules/windows/process_creation/proc_creation_win_lolbin_data_exfiltration_by_using_datasvcutil.yml","techniques":["T1567"],"cves":[]}],"kev_cves":[{"cveID":"CVE-2025-54309","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2024-11182","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2022-41082","state":"mapped","mapping_types":["secondary_impact"]}],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}