{"id":"T1048","name":"Exfiltration Over Alternative Protocol","url":"https://attack.mitre.org/techniques/T1048","tactics":["exfiltration"],"platforms":["ESXi","IaaS","Linux","macOS","Network Devices","Office Suite","SaaS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0131","stix_id":"x-mitre-detection-strategy--ed9ef930-ec1f-4e57-a110-9b647e2ca195","name":"Behavioral Detection Strategy for Exfiltration Over Alternative Protocol","url":"https://attack.mitre.org/detectionstrategies/DET0131","analytics":[{"id":"AN0367","stix_id":"x-mitre-analytic--1543bc4a-7614-417a-85b9-d67e3da0350c","name":"Analytic 0367","description":"Detects unusual outbound file transfer behavior using protocols like FTP, SMB, SMTP, or DNS, involving non-standard processes, off-hour activity, or uncommonly high volume.","url":"https://attack.mitre.org/detectionstrategies/DET0131#AN0367","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=3, 22","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=11","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Security","channel":"EventCode=4688","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-security"}],"mutable_elements":[{"field":"DataVolumeThresholdMB","description":"Set threshold for outbound volume (e.g., >50MB in a single connection)."},{"field":"ProtocolAllowList","description":"Allow-listed protocols in use for specific machines or users (e.g., FTP allowed for backups)."},{"field":"TimeWindow","description":"Define allowed time-of-day windows (e.g., flag after-hours file transfer)."},{"field":"ParentProcessAnomaly","description":"Identify anomalous parent-child process relationships (e.g., `winword.exe` spawning `ftp.exe`)."}],"live":true,"detection_strategies":["DET0131"],"techniques":["T1048"]},{"id":"AN0368","stix_id":"x-mitre-analytic--7402eb3b-9349-478a-a8e9-7ee72c4b67c5","name":"Analytic 0368","description":"Detects file exfiltration using tools like curl, scp, or custom binaries over protocols such as FTP, HTTP/S, or DNS tunneling, especially outside baseline user behavior.","url":"https://attack.mitre.org/detectionstrategies/DET0131#AN0368","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"},{"name":"auditd:SYSCALL","channel":"connect","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"auditd-syscall"},{"name":"auditd:SYSCALL","channel":"open","data_component":"DC0055","data_component_name":"File Access","log_source_slug":"auditd-syscall"},{"name":"auditd:SYSCALL","channel":"write","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"auditd-syscall"},{"name":"NSM:Flow","channel":"NetFlow/Zeek conn.log","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"ProtocolType","description":"Flag unexpected protocols (e.g., HTTP on port 53 or FTP traffic from non-standard tools)."},{"field":"UserContext","description":"Scope for privilege escalation or service account behavior."},{"field":"FileExtensionSensitivity","description":"Track movement of file types of interest (e.g., `.csv`, `.sql`, `.key`)."}],"live":true,"detection_strategies":["DET0131"],"techniques":["T1048"]},{"id":"AN0369","stix_id":"x-mitre-analytic--c545f39e-d1a2-4b0e-bdf1-6a84226557e9","name":"Analytic 0369","description":"Detects non-native file transfer via curl, Python scripts, or AppleScript using uncommon protocols like FTP, SMTP, or DNS exfiltration through mDNSResponder abuse.","url":"https://attack.mitre.org/detectionstrategies/DET0131#AN0369","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"log stream (subsystem: com.apple.system.networking)","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"macos-unifiedlog"},{"name":"macos:osquery","channel":"process_events","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-osquery"},{"name":"macos:osquery","channel":"file_events","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"macos-osquery"}],"mutable_elements":[{"field":"ProtocolUnusualnessScore","description":"Weight rarely-used protocols in user space."},{"field":"ExecutableBaselining","description":"Track which binaries usually call curl/nc and alert on deviation."}],"live":true,"detection_strategies":["DET0131"],"techniques":["T1048"]},{"id":"AN0370","stix_id":"x-mitre-analytic--8dbd751b-a2cf-418a-b409-daae78a250f8","name":"Analytic 0370","description":"Detects access to cloud APIs or CLI tools to move or sync files from sensitive buckets to external endpoints using protocols like HTTPS or S3 APIs.","url":"https://attack.mitre.org/detectionstrategies/DET0131#AN0370","platforms":["IaaS"],"log_source_references":[{"name":"AWS:CloudTrail","channel":"GetObject, CopyObject","data_component":"DC0025","data_component_name":"Cloud Storage Access","log_source_slug":"aws-cloudtrail"},{"name":"AWS:VPCFlowLogs","channel":"Outbound data flows","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"aws-vpcflowlogs"}],"mutable_elements":[{"field":"IAMRoleContext","description":"Detect unauthorized use of roles for cloud storage manipulation."},{"field":"GeoDestinationThreshold","description":"Alert on outbound flows to geo-locations not seen in training baseline."}],"live":true,"detection_strategies":["DET0131"],"techniques":["T1048"]},{"id":"AN0371","stix_id":"x-mitre-analytic--3810988a-78be-4628-a9a5-500020f9c075","name":"Analytic 0371","description":"Detects outbound traffic from hostd/vpxa or guest VM interfaces using unauthorized protocols such as FTP, HTTP POST bursts, or long-lived DNS tunnels.","url":"https://attack.mitre.org/detectionstrategies/DET0131#AN0371","platforms":["ESXi"],"log_source_references":[{"name":"esxi:hostd","channel":"logline inspection","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"esxi-hostd"},{"name":"esxi:vmkernel","channel":"protocol egress","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"esxi-vmkernel"}],"mutable_elements":[{"field":"GuestTrafficBaseline","description":"Expected protocols used by VMs attached to host interfaces."},{"field":"ServiceAccountProfile","description":"Unexpected network activity from hypervisor processes or monitoring agents."}],"live":true,"detection_strategies":["DET0131"],"techniques":["T1048"]}],"live":true,"version":"1.0","techniques":["T1048"]}],"sigma_rules":[{"id":"6ddff2e8-ea1a-45d0-8938-93dfc1d67ae7","title":"PUA - Restic Backup Tool Execution","author":"Nounou Mbeiri, Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"high","date":"2025-10-17","modified":null,"description":"Detects the execution of the Restic backup tool, which can be used for data exfiltration.\nThreat actors may leverage Restic to back up and exfiltrate sensitive data to remote storage locations, including cloud services.\nIf not legitimately used in the enterprise environment, its presence may indicate malicious activity.\n","references":["https://thedfirreport.com/2024/09/30/nitrogen-campaign-drops-sliver-and-ends-with-blackcat-ransomware/#exfiltration","https://restic.net/","https://restic.readthedocs.io/en/stable/030_preparing_a_new_repo.html"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.exfiltration","attack.t1048","attack.t1567.002"],"path":"rules/windows/process_creation/proc_creation_win_pua_restic.yml","techniques":["T1048","T1567.002"],"cves":[]},{"id":"7674f8ef-7141-4cf0-a311-ee359264c64c","title":"Winscp Execution From Non Standard Folder","author":"frack113","status":"experimental","level":"medium","date":"2025-10-12","modified":null,"description":"Detects the execution of Winscp from an a non standard folder. This could indicate the execution of Winscp portable.","references":["https://blogs.blackberry.com/en/2024/07/akira-ransomware-targets-the-latam-airline-industry"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.exfiltration","attack.t1048","detection.threat-hunting"],"path":"rules-threat-hunting/windows/process_creation/proc_creation_win_winscp_portable_execution.yml","techniques":["T1048"],"cves":[]},{"id":"855bc8b5-2ae8-402e-a9ed-b889e6df1900","title":"Copy From Or To Admin Share Or Sysvol Folder","author":"Florian Roth (Nextron Systems), oscd.community, Teymur Kheirkhabarov @HeirhabarovT, Zach Stanford @svch0st, Nasreddine Bencherchali","status":"test","level":"medium","date":"2019-12-30","modified":"2025-10-22","description":"Detects a copy command or a copy utility execution to or from an Admin share or remote","references":["https://twitter.com/SBousseaden/status/1211636381086339073","https://drive.google.com/file/d/1lKya3_mLnR3UQuCoiYruO3qgu052_iS_/view","https://www.elastic.co/guide/en/security/current/remote-file-copy-to-a-hidden-share.html","https://www.microsoft.com/en-us/security/blog/2022/10/18/defenders-beware-a-case-for-post-ransomware-investigations/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.lateral-movement","attack.collection","attack.exfiltration","attack.t1039","attack.t1048","attack.t1021.002"],"path":"rules/windows/process_creation/proc_creation_win_susp_copy_lateral_movement.yml","techniques":["T1039","T1048","T1021.002"],"cves":[]},{"id":"8e4cf0e5-aa5d-4dc3-beff-dc26917744a9","title":"Tap Driver Installation","author":"Daniil Yugoslavskiy, Ian Davis, oscd.community","status":"test","level":"medium","date":"2019-10-24","modified":"2022-12-25","description":"Well-known TAP software installation. Possible preparation for data exfiltration using tunnelling techniques","references":["https://community.openvpn.net/openvpn/wiki/ManagingWindowsTAPDrivers"],"logsource":{"product":"windows","service":"system"},"tags":["attack.exfiltration","attack.t1048"],"path":"rules/windows/builtin/system/service_control_manager/win_system_service_install_tap_driver.yml","techniques":["T1048"],"cves":[]},{"id":"99793437-3e16-439b-be0f-078782cf953d","title":"Tap Installer Execution","author":"Daniil Yugoslavskiy, Ian Davis, oscd.community","status":"test","level":"medium","date":"2019-10-24","modified":"2023-12-11","description":"Well-known TAP software installation. Possible preparation for data exfiltration using tunneling techniques","references":["https://community.openvpn.net/openvpn/wiki/ManagingWindowsTAPDrivers"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.exfiltration","attack.t1048"],"path":"rules/windows/process_creation/proc_creation_win_tapinstall_execution.yml","techniques":["T1048"],"cves":[]},{"id":"9c8afa4d-0022-48f0-9456-3712466f9701","title":"Tap Driver Installation - Security","author":"Daniil Yugoslavskiy, Ian Davis, oscd.community","status":"test","level":"low","date":"2019-10-24","modified":"2022-11-29","description":"Detects the installation of a well-known TAP driver service. This could be a sign of potential preparation for data exfiltration using tunnelling techniques.\n","references":["https://community.openvpn.net/openvpn/wiki/ManagingWindowsTAPDrivers"],"logsource":{"product":"windows","service":"security"},"tags":["attack.exfiltration","attack.t1048"],"path":"rules/windows/builtin/security/win_security_tap_driver_installation.yml","techniques":["T1048"],"cves":[]},{"id":"a8322756-015c-42e7-afb1-436e85ed3ff5","title":"DNS TOR Proxies","author":"Saw Winn Naung , Azure-Sentinel","status":"test","level":"medium","date":"2021-08-15","modified":"2025-09-12","description":"Identifies IPs performing DNS lookups associated with common Tor proxies.","references":["https://github.com/Azure/Azure-Sentinel/blob/f99542b94afe0ad2f19a82cc08262e7ac8e1428e/Detections/ASimDNS/imDNS_TorProxies.yaml"],"logsource":{"product":"zeek","service":"dns"},"tags":["attack.exfiltration","attack.t1048"],"path":"rules/network/zeek/zeek_dns_torproxy.yml","techniques":["T1048"],"cves":[]},{"id":"ab9e3b40-0c85-4ba1-aede-455d226fd124","title":"Suspicious Redirection to Local Admin Share","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2022-01-16","modified":"2023-12-28","description":"Detects a suspicious output redirection to the local admins share, this technique is often found in malicious scripts or hacktool stagers","references":["https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/","http://blog.talosintelligence.com/2022/09/lazarus-three-rats.html"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.exfiltration","attack.t1048"],"path":"rules/windows/process_creation/proc_creation_win_susp_redirect_local_admin_share.yml","techniques":["T1048"],"cves":[]},{"id":"ac5a4e3f-7f9d-6abc-d8ea-3b4c5f6a7b8c","title":"TanStack Supply-Chain Attack DNS Indicators","author":"Leonardo Gasparini","status":"experimental","level":"medium","date":"2026-05-12","modified":null,"description":"Detects DNS queries to attacker-controlled infrastructure used by the Mini Shai-Hulud campaign targeting TanStack npm packages along with other packages such as mistralai, uipath and so on.\nThe domain git-tanstack.com (registered May 9, 2026) hosted secondary payloads including transformers.pyz.\nThe filev2.getsession.org endpoint was used for credential exfiltration via the Session protocol.\n","references":["https://socket.dev/blog/tanstack-npm-packages-compromised-mini-shai-hulud-supply-chain-attack","https://socket.dev/supply-chain-attacks/mini-shai-hulud","https://safedep.io/mass-npm-supply-chain-attack-tanstack-mistral/"],"logsource":{"product":"windows","category":"dns_query"},"tags":["attack.command-and-control","attack.t1071.001","attack.exfiltration","attack.t1048","detection.emerging-threats"],"path":"rules-emerging-threats/2026/Malware/TanStack-Supply-Chain/dns_query_win_malware_tanstack_supply_chain_c2.yml","techniques":["T1071.001","T1048"],"cves":[]},{"id":"c1477deb-37cf-4439-9ffb-44499acb89d0","title":"FTP Connection Open Attempt Via Winscp CLI","author":"frack113","status":"experimental","level":"medium","date":"2025-10-12","modified":null,"description":"Detects the execution of Winscp with the \"-command\" and the \"open\" flags in order to open an FTP connection. Akira ransomware was seen using this technique in order to exfiltrate data.","references":["https://blogs.blackberry.com/en/2024/07/akira-ransomware-targets-the-latam-airline-industry"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.exfiltration","attack.t1048","detection.threat-hunting"],"path":"rules-threat-hunting/windows/process_creation/proc_creation_win_winscp_command_open_ftp.yml","techniques":["T1048"],"cves":[]},{"id":"c615d676-f655-46b9-b913-78729021e5d7","title":"Data Export From MSSQL Table Via BCP.EXE","author":"Omar Khaled (@beacon_exe), MahirAli Khan (in/mahiralikhan), Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2024-08-20","modified":null,"description":"Detects the execution of the BCP utility in order to export data from the database.\nAttackers were seen saving their malware to a database column or table and then later extracting it via \"bcp.exe\" into a file.\n","references":["https://docs.microsoft.com/en-us/sql/tools/bcp-utility","https://asec.ahnlab.com/en/61000/","https://asec.ahnlab.com/en/78944/","https://www.huntress.com/blog/attacking-mssql-servers","https://www.huntress.com/blog/attacking-mssql-servers-pt-ii","https://news.sophos.com/en-us/2024/08/07/sophos-mdr-hunt-tracks-mimic-ransomware-campaign-against-organizations-in-india/","https://research.nccgroup.com/2018/03/10/apt15-is-alive-and-strong-an-analysis-of-royalcli-and-royaldns/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.exfiltration","attack.t1048"],"path":"rules/windows/process_creation/proc_creation_win_bcp_export_data.yml","techniques":["T1048"],"cves":[]},{"id":"d59d7842-9a21-4bc6-ba98-64bfe0091355","title":"Powershell DNSExfiltration","author":"frack113","status":"test","level":"high","date":"2022-01-07","modified":null,"description":"DNSExfiltrator allows for transferring (exfiltrate) a file over a DNS request covert channel","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1048/T1048.md#atomic-test-3---dnsexfiltration-doh","https://github.com/Arno0x/DNSExfiltrator"],"logsource":{"product":"windows","category":"ps_script"},"tags":["attack.exfiltration","attack.t1048"],"path":"rules/windows/powershell/powershell_script/posh_ps_invoke_dnsexfiltration.yml","techniques":["T1048"],"cves":[]}],"kev_cves":[{"cveID":"CVE-2017-6742","state":"mapped","mapping_types":["secondary_impact"]},{"cveID":"CVE-2022-26500","state":"mapped","mapping_types":["secondary_impact"]},{"cveID":"CVE-2022-26501","state":"mapped","mapping_types":["secondary_impact"]},{"cveID":"CVE-2013-0641","state":"mapped","mapping_types":["secondary_impact"]}],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}