ATT&CK · T1020
Automated Exfiltration
Tactics: exfiltration
About
Adversaries may exfiltrate data, such as sensitive documents, through the use of automated processing after being gathered during Collection. When automated exfiltration is used, other exfiltration techniques likely apply as well to transfer the information out of the network, such as Exfiltration Over C2 Channel and Exfiltration Over Alternative Protocol.
Platforms: Linux, macOS, Network Devices, WindowsMITRE ATT&CK ↗
Used by actors
7 known groups
Software
20 malware/tools implement this
CosmicDukeRoverTINYTYPHONUSBStealerEmpireEburyLightNeuronMacheteAttorShimRatReporterTajMahalStrongPityCrutchDokiPeppyOutSteelRaccoon StealerSolarStrelaStealerHannotog
Corpus indicators tagged with this technique
52 indicators in the corpus carry T1020.
Showing the top 30 by severity of 52.