T1029 — Scheduled Transfer
T1029: Scheduled Transfer
MITRE ATT&CK® Enterprise technique
| Tactics | Exfiltration |
| Platforms | Linux, macOS, Windows |
| Permissions required | — |
| Version | 1.1 |
Description
Adversaries may schedule data exfiltration to be performed only at certain times of day or at certain intervals. This could be done to blend traffic patterns with normal activity or availability.
When scheduled exfiltration is used, other exfiltration techniques likely apply as well to transfer the information out of the network, such as Exfiltration Over C2 Channel or Exfiltration Over Alternative Protocol.
Detection
(no detection guidance published)
Data sources
- (none listed)
References
- ATT&CK page: https://attack.mitre.org/techniques/T1029
- ATT&CK Enterprise matrix: https://attack.mitre.org/matrices/enterprise/
See all 697 pages under Attacker techniques (ATT&CK) →
Related pages
Browse by topic
Every page in the corpus, grouped. Search finds one page; this shows what else is here.