Techniques › T1020 › T1020.001
T1020.001 Traffic Duplication
exfiltration — Network Devices, IaaS · attack.mitre.org · JSON
1
MITRE detection strategy
2
analytics
0
Sigma rules tagged attack.t1020.001
0
KEV CVEs mapped here
<p>Adversaries may leverage traffic mirroring in order to automate data exfiltration over compromised infrastructure. Traffic mirroring is a native feature for some devices, often used for network analysis. For example, devices may be configured to forward network traffic to one or more destinations for analysis by a network analyzer or other monitoring device.</p><p>Adversaries may abuse traffic mirroring to mirror or redirect network traffic through other infrastructure they control. Malicious modifications to network devices to enable traffic redirection may be possible through ROMMONkit or Patch System Image.</p><p>Many cloud-based environments also support traffic mirroring. For example, AWS Traffic Mirroring, GCP Packet Mirroring, and Azure vTap allow users to define specified instances to collect traffic from and specified targets to send collected traffic to.</p><p>Adversaries may use traffic duplication in conjunction with Network Sniffing, Input Capture, or Adversary-in-the-Middle depending on the goals and objectives of the adversary.</p>
KEV CVEs mapped to this technique · CTID Mappings Explorer
None. No KEV entry in the public mapping names this technique. Given that 74.7% of KEV has no mapping at all, this says more about the mapping than about the technique.
Detection strategy · ATT&CK Enterprise v19.2
- DET0403 Detection Strategy for Traffic Duplication via Mirroring in IaaS and Network Devices v1.0
AN1131 IaaSConfiguration changes to virtual TAP/mirror policies that forward traffic to unapproved destinations. Detection correlates management plane API calls with mirrored traffic observation.AWS:CloudTrail
CreateTrafficMirrorSession or ModifyTrafficMirrorTarget→ DC0078 Network Traffic FlowAWS:VPCFlowLogsTraffic observed on mirror destination instance→ DC0082 Network Connection CreationTunable:TimeWindowMirrorDestinationCIDRUserIdentityAN1132 Network DevicesUnauthorized mirroring sessions initiated on routers/switches (e.g., viamonitor session,mirror port) coupled with outbound traffic from mirrored interface to unexpected destinations.networkdevice:syslogConfig change: CLI/NETCONF/SNMP – 'monitor session', 'mirror port'→ DC0078 Network Traffic Flownetworkdevice:FlowTraffic from mirrored interface to mirror target IP→ DC0082 Network Connection CreationTunable:ConfigChangeTypeMirrorDestinationPortDeviceRole
Sigma rules · SigmaHQ da9bb07d64, tag attack.t1020.001
No Sigma rule carries this tag. MITRE publishes a detection strategy above, so the behaviour is specified; what is missing is public detection content.
Rules tagged at the parent level (attack.t1020) 10
These target the parent technique, not this sub-technique specifically. Listed for completeness, not counted as coverage.
Author: Romain Gaillard (@romain-gaillard)
· 2024-07-29 · logsource: product=github service=audit · 04ad83ef-1a37-4c10-b57a-81092164bf33
Detects when a repository or an organization is being transferred to another location.
Author: Nasreddine Bencherchali (Nextron Systems), Marco Pedrinazzi (@pedrinazziM) (InTheCyber)
· 2026-03-01 · logsource: product=windows category=ps_script · 0c7686d5-c74e-4292-b224-2a08e956ebc4
Detects email forwarding or redirecting activity via ExchangePowerShell Cmdlet
Author: Ivan Saakov
· 2024-12-06 · logsource: product=aws service=cloudtrail · 457cc9ac-d8e6-4d1d-8c0e-251d0f11a74c
Detects modifications to an RDS cluster or its deletion, which may indicate potential data exfiltration attempts, unauthorized access, or exposure of sensitive information.
Author: Romain Gaillard (@romain-gaillard)
· 2024-07-29 · logsource: product=github service=audit · 69b3bd1e-b38a-462f-9a23-fbdbf63d2294
Detects when the policy allowing forks of private and internal repositories is changed (enabled or cleared).
Author: Austin Songer @austinsonger
· 2021-08-22 (modified 2022-10-09) · logsource: product=m365 service=threat_management · 6c220477-0b5b-4b25-bb90-66183b4089e8
Detects when a Microsoft Cloud App Security reported suspicious email forwarding rules, for example, if a user created an inbox rule that forwards a copy of all emails to an external address.
Author: faloker
· 2020-02-12 (modified 2022-10-05) · logsource: product=aws service=cloudtrail · 8a63cdd4-6207-414a-85bc-7e032bd3c1a2
Detects the change of database master password. It may be a part of data exfiltration.
Author: faloker
· 2020-02-12 (modified 2022-10-09) · logsource: product=aws service=cloudtrail · c3f265c7-ff03-4056-8ab2-d486227b4599
Detects the recovery of a new public database instance from a snapshot. It may be a part of data exfiltration.
Author: RedCanary Team (idea), Harjot Singh @cyb3rjy0t
· 2023-10-11 (modified 2024-11-17) · logsource: product=m365 service=audit · c726e007-2cd0-4a55-abfb-79730fbedee5
Detects email forwarding or redirecting activity in O365 Audit logs.
Author: frack113
· 2022-01-07 (modified 2025-07-18) · logsource: product=windows category=ps_script · d2e3f2f6-7e09-4bf2-bc5d-90186809e7fb
Detects PowerShell scripts leveraging the "Invoke-WebRequest" cmdlet to send data via either "PUT" or "POST" method.
Author: Nasreddine Bencherchali (Nextron Systems)
· 2023-05-05 · logsource: product=windows category=ps_script · fbc5e92f-3044-4e73-a5c6-1c4359b539de
Detects PowerShell scripts that have capabilities to read files, loop through them and resolve DNS host entries.