T1011.001 — Exfiltration Over Bluetooth
T1011.001: Exfiltration Over Bluetooth
MITRE ATT&CK® Enterprise technique
| Tactics | Exfiltration |
| Platforms | Linux, macOS, Windows |
| Permissions required | — |
| Version | 1.2 |
| Parent technique | T1011 |
Description
Adversaries may attempt to exfiltrate data over Bluetooth rather than the command and control channel. If the command and control network is a wired Internet connection, an adversary may opt to exfiltrate data using a Bluetooth communication channel.
Adversaries may choose to do this if they have sufficient access and proximity. Bluetooth connections might not be secured or defended as well as the primary Internet-connected channel because it is not routed through the same enterprise network.
Detection
(no detection guidance published)
Data sources
- (none listed)
References
- ATT&CK page: https://attack.mitre.org/techniques/T1011/001
- ATT&CK Enterprise matrix: https://attack.mitre.org/matrices/enterprise/