Skip to content
Every technique
T1020Detection written

Automated Exfiltration

ExfiltrationLinux, macOS, Network Devices, Windows

Where this stands

One published detection covers this technique. Every one is unverified — no rule on Siemphony has been executed against real telemetry.

What the technique is

Adversaries may exfiltrate data, such as sensitive documents, through the use of automated processing after being gathered during Collection. When automated exfiltration is used, other exfiltration techniques likely apply as well to transfer the information out of the network, such as Exfiltration Over C2 Channel and Exfiltration Over Alternative Protocol.

Read it on attack.mitre.org

What MITRE says you would watch

  • AN1113

    Detection of automated tools or scripts periodically transmitting data to external destinations using scheduled tasks or background processes.

  • AN1114

    Background scripts (e.g., via cron) or daemons transmitting data repeatedly to remote IPs or URLs.

  • AN1115

    Observation of LaunchAgents or LaunchDaemons establishing periodic external connections indicative of automated data transfer.

Technique names and descriptions © MITRE ATT&CK®, CC BY 4.0. Not endorsed by MITRE.