FORENSIA

ATT&CK · T1029

Scheduled Transfer

Tactics: exfiltration

About

Adversaries may schedule data exfiltration to be performed only at certain times of day or at certain intervals. This could be done to blend traffic patterns with normal activity or availability. When scheduled exfiltration is used, other exfiltration techniques likely apply as well to transfer the information out of the network, such as Exfiltration Over C2 Channel or Exfiltration Over Alternative Protocol.

Platforms: Linux, macOS, WindowsMITRE ATT&CK ↗

Used by actors

1 known groups

Software

17 malware/tools implement this

ADVSTORESHELLComRATCobalt StrikeDipsindLinfoPOWERSTATSKazuarjRATLightNeuronMacheteShimRatShadowPadChrommmeTinyTurlaFlagproSharkNinja

Corpus indicators tagged with this technique

0 indicators in the corpus carry T1029.

No corpus indicators are tagged with this technique yet.