{"id":"T1020","name":"Automated Exfiltration","url":"https://attack.mitre.org/techniques/T1020","tactics":["exfiltration"],"platforms":["Linux","macOS","Network Devices","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0397","stix_id":"x-mitre-detection-strategy--da5ff985-fd0d-438f-8498-c8dc195f741a","name":"Automated Exfiltration Detection Strategy","url":"https://attack.mitre.org/detectionstrategies/DET0397","analytics":[{"id":"AN1113","stix_id":"x-mitre-analytic--4a92d2e9-fc28-4eac-9b3d-113e74d7bf2d","name":"Analytic 1113","description":"Detection of automated tools or scripts periodically transmitting data to external destinations using scheduled tasks or background processes.","url":"https://attack.mitre.org/detectionstrategies/DET0397#AN1113","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4688","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Sysmon","channel":"EventCode=3, 22","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"TimeWindow","description":"Used to detect repeated exfil activity over intervals (e.g., every 5 minutes)."},{"field":"DestinationIP","description":"Can be tuned to filter known internal or trusted destinations."}],"live":true,"detection_strategies":["DET0397"],"techniques":["T1020"]},{"id":"AN1114","stix_id":"x-mitre-analytic--31adce9b-8935-4abf-aaf2-0a13047e25e4","name":"Analytic 1114","description":"Background scripts (e.g., via cron) or daemons transmitting data repeatedly to remote IPs or URLs.","url":"https://attack.mitre.org/detectionstrategies/DET0397#AN1114","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"},{"name":"NSM:Flow","channel":"Outbound Connections","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"CronJobInterval","description":"Tunable time range for recurring tasks seen creating outbound connections."},{"field":"UserContext","description":"Tunable for scope — service accounts vs user accounts."}],"live":true,"detection_strategies":["DET0397"],"techniques":["T1020"]},{"id":"AN1115","stix_id":"x-mitre-analytic--031ed94b-50d9-451e-a853-29ee8d845773","name":"Analytic 1115","description":"Observation of LaunchAgents or LaunchDaemons establishing periodic external connections indicative of automated data transfer.","url":"https://attack.mitre.org/detectionstrategies/DET0397#AN1115","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"process: exec","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"network","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"macos-unifiedlog"},{"name":"macos:cron","channel":"cron/launchd","data_component":"DC0001","data_component_name":"Scheduled Job Creation","log_source_slug":"macos-cron"}],"mutable_elements":[{"field":"LaunchInterval","description":"Frequency of task recurrence linked to external communication."},{"field":"DestinationPort","description":"Port number used for detection filtering."}],"live":true,"detection_strategies":["DET0397"],"techniques":["T1020"]}],"live":true,"version":"1.0","techniques":["T1020"]}],"sigma_rules":[{"id":"04ad83ef-1a37-4c10-b57a-81092164bf33","title":"Github Repository/Organization Transferred","author":"Romain Gaillard (@romain-gaillard)","status":"test","level":"medium","date":"2024-07-29","modified":null,"description":"Detects when a repository or an organization is being transferred to another location.","references":["https://docs.github.com/en/repositories/creating-and-managing-repositories/transferring-a-repository","https://docs.github.com/en/organizations/managing-organization-settings/transferring-organization-ownership","https://docs.github.com/en/migrations","https://docs.github.com/en/enterprise-cloud@latest/admin/monitoring-activity-in-your-enterprise/reviewing-audit-logs-for-your-enterprise/audit-log-events-for-your-enterprise#migration"],"logsource":{"product":"github","service":"audit"},"tags":["attack.persistence","attack.exfiltration","attack.t1020","attack.t1537"],"path":"rules/application/github/audit/github_repo_or_org_transferred.yml","techniques":["T1020","T1537"],"cves":[]},{"id":"0c7686d5-c74e-4292-b224-2a08e956ebc4","title":"Mail Forwarding/Redirecting Activity Via ExchangePowerShell Cmdlet","author":"Nasreddine Bencherchali (Nextron Systems), Marco Pedrinazzi (@pedrinazziM) (InTheCyber)","status":"experimental","level":"medium","date":"2026-03-01","modified":null,"description":"Detects email forwarding or redirecting activity via ExchangePowerShell Cmdlet","references":["https://redcanary.com/blog/email-forwarding-rules/","https://github.com/PwC-IR/Business-Email-Compromise-Guide/blob/fe29ce06aef842efe4eb448c26bbe822bf5b895d/PwC-Business_Email_Compromise-Guide.pdf"],"logsource":{"product":"windows","category":"ps_script"},"tags":["attack.collection","attack.stealth","attack.t1114.003","attack.t1564.008","attack.exfiltration","attack.t1020","detection.threat-hunting"],"path":"rules-threat-hunting/windows/powershell/powershell_script/posh_ps_email_forwarding_activity.yml","techniques":["T1114.003","T1564.008","T1020"],"cves":[]},{"id":"457cc9ac-d8e6-4d1d-8c0e-251d0f11a74c","title":"Modification or Deletion of an AWS RDS Cluster","author":"Ivan Saakov","status":"experimental","level":"high","date":"2024-12-06","modified":null,"description":"Detects modifications to an RDS cluster or its deletion, which may indicate potential data exfiltration attempts, unauthorized access, or exposure of sensitive information.","references":["https://docs.aws.amazon.com/AmazonRDS/latest/APIReference/API_ModifyDBCluster.html","https://docs.aws.amazon.com/AmazonRDS/latest/APIReference/API_DeleteDBCluster.html","https://cloud.hacktricks.xyz/pentesting-cloud/aws-security/aws-privilege-escalation/aws-rds-privesc#rds-modifydbinstance"],"logsource":{"product":"aws","service":"cloudtrail"},"tags":["attack.exfiltration","attack.t1020"],"path":"rules/cloud/aws/cloudtrail/aws_rds_dbcluster_actions.yml","techniques":["T1020"],"cves":[]},{"id":"69b3bd1e-b38a-462f-9a23-fbdbf63d2294","title":"Github Fork Private Repositories Setting Enabled/Cleared","author":"Romain Gaillard (@romain-gaillard)","status":"test","level":"medium","date":"2024-07-29","modified":null,"description":"Detects when the policy allowing forks of private and internal repositories is changed (enabled or cleared).\n","references":["https://docs.github.com/en/enterprise-cloud@latest/admin/monitoring-activity-in-your-enterprise/reviewing-audit-logs-for-your-enterprise/audit-log-events-for-your-enterprise#private_repository_forking"],"logsource":{"product":"github","service":"audit"},"tags":["attack.persistence","attack.exfiltration","attack.t1020","attack.t1537"],"path":"rules/application/github/audit/github_fork_private_repos_enabled_or_cleared.yml","techniques":["T1020","T1537"],"cves":[]},{"id":"6c220477-0b5b-4b25-bb90-66183b4089e8","title":"Suspicious Inbox Forwarding","author":"Austin Songer @austinsonger","status":"test","level":"low","date":"2021-08-22","modified":"2022-10-09","description":"Detects when a Microsoft Cloud App Security reported suspicious email forwarding rules, for example, if a user created an inbox rule that forwards a copy of all emails to an external address.","references":["https://learn.microsoft.com/en-us/defender-cloud-apps/anomaly-detection-policy","https://learn.microsoft.com/en-us/defender-cloud-apps/policy-template-reference"],"logsource":{"product":"m365","service":"threat_management"},"tags":["attack.exfiltration","attack.t1020"],"path":"rules/cloud/m365/threat_management/microsoft365_susp_inbox_forwarding.yml","techniques":["T1020"],"cves":[]},{"id":"8a63cdd4-6207-414a-85bc-7e032bd3c1a2","title":"AWS RDS Master Password Change","author":"faloker","status":"test","level":"medium","date":"2020-02-12","modified":"2022-10-05","description":"Detects the change of database master password. It may be a part of data exfiltration.","references":["https://github.com/RhinoSecurityLabs/pacu/blob/866376cd711666c775bbfcde0524c817f2c5b181/pacu/modules/rds__explore_snapshots/main.py"],"logsource":{"product":"aws","service":"cloudtrail"},"tags":["attack.exfiltration","attack.t1020"],"path":"rules/cloud/aws/cloudtrail/aws_rds_change_master_password.yml","techniques":["T1020"],"cves":[]},{"id":"c3f265c7-ff03-4056-8ab2-d486227b4599","title":"Restore Public AWS RDS Instance","author":"faloker","status":"test","level":"high","date":"2020-02-12","modified":"2022-10-09","description":"Detects the recovery of a new public database instance from a snapshot. It may be a part of data exfiltration.","references":["https://github.com/RhinoSecurityLabs/pacu/blob/866376cd711666c775bbfcde0524c817f2c5b181/pacu/modules/rds__explore_snapshots/main.py"],"logsource":{"product":"aws","service":"cloudtrail"},"tags":["attack.exfiltration","attack.t1020"],"path":"rules/cloud/aws/cloudtrail/aws_rds_public_db_restore.yml","techniques":["T1020"],"cves":[]},{"id":"c726e007-2cd0-4a55-abfb-79730fbedee5","title":"Mail Forwarding/Redirecting Activity In O365","author":"RedCanary Team (idea), Harjot Singh @cyb3rjy0t","status":"test","level":"medium","date":"2023-10-11","modified":"2024-11-17","description":"Detects email forwarding or redirecting activity in O365 Audit logs.","references":["https://redcanary.com/blog/email-forwarding-rules/","https://github.com/PwC-IR/Business-Email-Compromise-Guide/blob/fe29ce06aef842efe4eb448c26bbe822bf5b895d/PwC-Business_Email_Compromise-Guide.pdf"],"logsource":{"product":"m365","service":"audit"},"tags":["attack.collection","attack.stealth","attack.t1114.003","attack.t1564.008","attack.exfiltration","attack.t1020","detection.threat-hunting"],"path":"rules-threat-hunting/cloud/m365/audit/microsoft365_susp_email_forwarding_activity.yml","techniques":["T1114.003","T1564.008","T1020"],"cves":[]},{"id":"d2e3f2f6-7e09-4bf2-bc5d-90186809e7fb","title":"PowerShell Script With File Upload Capabilities","author":"frack113","status":"test","level":"low","date":"2022-01-07","modified":"2025-07-18","description":"Detects PowerShell scripts leveraging the \"Invoke-WebRequest\" cmdlet to send data via either \"PUT\" or \"POST\" method.","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1020/T1020.md","https://www.w3.org/Protocols/rfc2616/rfc2616-sec9.html","https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.utility/invoke-webrequest?view=powershell-7.4"],"logsource":{"product":"windows","category":"ps_script"},"tags":["attack.exfiltration","attack.t1020"],"path":"rules/windows/powershell/powershell_script/posh_ps_script_with_upload_capabilities.yml","techniques":["T1020"],"cves":[]},{"id":"fbc5e92f-3044-4e73-a5c6-1c4359b539de","title":"PowerShell Script With File Hostname Resolving Capabilities","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2023-05-05","modified":null,"description":"Detects PowerShell scripts that have capabilities to read files, loop through them and resolve DNS host entries.","references":["https://www.fortypoundhead.com/showcontent.asp?artid=24022","https://labs.withsecure.com/publications/fin7-target-veeam-servers"],"logsource":{"product":"windows","category":"ps_script"},"tags":["attack.exfiltration","attack.t1020"],"path":"rules/windows/powershell/powershell_script/posh_ps_resolve_list_of_ip_from_file.yml","techniques":["T1020"],"cves":[]}],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}