kevmap

TechniquesT1020 › T1020.001

T1020.001 Traffic Duplication

exfiltration — Network Devices, IaaS · attack.mitre.org · JSON

1
MITRE detection strategy
2
analytics
0
Sigma rules tagged attack.t1020.001
0
KEV CVEs mapped here
<p>Adversaries may leverage traffic mirroring in order to automate data exfiltration over compromised infrastructure. Traffic mirroring is a native feature for some devices, often used for network analysis. For example, devices may be configured to forward network traffic to one or more destinations for analysis by a network analyzer or other monitoring device.</p><p>Adversaries may abuse traffic mirroring to mirror or redirect network traffic through other infrastructure they control. Malicious modifications to network devices to enable traffic redirection may be possible through ROMMONkit or Patch System Image.</p><p>Many cloud-based environments also support traffic mirroring. For example, AWS Traffic Mirroring, GCP Packet Mirroring, and Azure vTap allow users to define specified instances to collect traffic from and specified targets to send collected traffic to.</p><p>Adversaries may use traffic duplication in conjunction with Network Sniffing, Input Capture, or Adversary-in-the-Middle depending on the goals and objectives of the adversary.</p>

KEV CVEs mapped to this technique · CTID Mappings Explorer

None. No KEV entry in the public mapping names this technique. Given that 74.7% of KEV has no mapping at all, this says more about the mapping than about the technique.

Detection strategy · ATT&CK Enterprise v19.2

Sigma rules · SigmaHQ da9bb07d64, tag attack.t1020.001

No Sigma rule carries this tag. MITRE publishes a detection strategy above, so the behaviour is specified; what is missing is public detection content.

Rules tagged at the parent level (attack.t1020) 10

These target the parent technique, not this sub-technique specifically. Listed for completeness, not counted as coverage.

Author: Romain Gaillard (@romain-gaillard) · 2024-07-29 · logsource: product=github service=audit · 04ad83ef-1a37-4c10-b57a-81092164bf33
Detects when a repository or an organization is being transferred to another location.
Techniques: T1020T1537
Author: Nasreddine Bencherchali (Nextron Systems), Marco Pedrinazzi (@pedrinazziM) (InTheCyber) · 2026-03-01 · logsource: product=windows category=ps_script · 0c7686d5-c74e-4292-b224-2a08e956ebc4
Detects email forwarding or redirecting activity via ExchangePowerShell Cmdlet
Author: Ivan Saakov · 2024-12-06 · logsource: product=aws service=cloudtrail · 457cc9ac-d8e6-4d1d-8c0e-251d0f11a74c
Detects modifications to an RDS cluster or its deletion, which may indicate potential data exfiltration attempts, unauthorized access, or exposure of sensitive information.
Techniques: T1020
Author: Romain Gaillard (@romain-gaillard) · 2024-07-29 · logsource: product=github service=audit · 69b3bd1e-b38a-462f-9a23-fbdbf63d2294
Detects when the policy allowing forks of private and internal repositories is changed (enabled or cleared).
Techniques: T1020T1537
Author: Austin Songer @austinsonger · 2021-08-22 (modified 2022-10-09) · logsource: product=m365 service=threat_management · 6c220477-0b5b-4b25-bb90-66183b4089e8
Detects when a Microsoft Cloud App Security reported suspicious email forwarding rules, for example, if a user created an inbox rule that forwards a copy of all emails to an external address.
Techniques: T1020
Author: faloker · 2020-02-12 (modified 2022-10-05) · logsource: product=aws service=cloudtrail · 8a63cdd4-6207-414a-85bc-7e032bd3c1a2
Detects the change of database master password. It may be a part of data exfiltration.
Techniques: T1020
Author: faloker · 2020-02-12 (modified 2022-10-09) · logsource: product=aws service=cloudtrail · c3f265c7-ff03-4056-8ab2-d486227b4599
Detects the recovery of a new public database instance from a snapshot. It may be a part of data exfiltration.
Techniques: T1020
Author: RedCanary Team (idea), Harjot Singh @cyb3rjy0t · 2023-10-11 (modified 2024-11-17) · logsource: product=m365 service=audit · c726e007-2cd0-4a55-abfb-79730fbedee5
Detects email forwarding or redirecting activity in O365 Audit logs.
Author: frack113 · 2022-01-07 (modified 2025-07-18) · logsource: product=windows category=ps_script · d2e3f2f6-7e09-4bf2-bc5d-90186809e7fb
Detects PowerShell scripts leveraging the "Invoke-WebRequest" cmdlet to send data via either "PUT" or "POST" method.
Techniques: T1020
Author: Nasreddine Bencherchali (Nextron Systems) · 2023-05-05 · logsource: product=windows category=ps_script · fbc5e92f-3044-4e73-a5c6-1c4359b539de
Detects PowerShell scripts that have capabilities to read files, loop through them and resolve DNS host entries.
Techniques: T1020