Skip to the content.

back

Find sigma rule :heavy_check_mark:

Attack: Automated Exfiltration

Adversaries may exfiltrate data, such as sensitive documents, through the use of automated processing after being gathered during Collection.(Citation: ESET Gamaredon June 2020)

When automated exfiltration is used, other exfiltration techniques likely apply as well to transfer the information out of the network, such as Exfiltration Over C2 Channel and Exfiltration Over Alternative Protocol.

MITRE

Tactic

technique

Test : IcedID Botnet HTTP PUT

OS

Description:

Creates a text file Tries to upload to a server via HTTP PUT method with ContentType Header Deletes a created file

Executor

powershell

Sigma Rule

back