ATT&CK · T1567
Exfiltration Over Web Service
Tactics: exfiltration
About
Adversaries may use an existing, legitimate external Web service to exfiltrate data rather than their primary command and control channel. Popular Web services acting as an exfiltration mechanism may give a significant amount of cover due to the likelihood that hosts within a network are already communicating with them prior to compromise. Firewall rules may also already exist to permit traffic to these services. Web service providers also commonly use SSL/TLS encryption, giving adversaries an added level of protection.
Used by actors
4 known groups
Software
7 malware/tools implement this
Corpus indicators tagged with this technique
310 indicators in the corpus carry T1567.
Showing the top 30 by severity of 310.