T1567.001 — Exfiltration to Code Repository
T1567.001: Exfiltration to Code Repository
MITRE ATT&CK® Enterprise technique
| Tactics | Exfiltration |
| Platforms | ESXi, Linux, macOS, Windows |
| Permissions required | — |
| Version | 1.2 |
| Parent technique | T1567 |
Description
Adversaries may exfiltrate data to a code repository rather than over their primary command and control channel. Code repositories are often accessible via an API (ex: https://api.github.com). Access to these APIs are often over HTTPS, which gives the adversary an additional level of protection.
Exfiltration to a code repository can also provide a significant amount of cover to the adversary if it is a popular service already used by hosts within the network.
Detection
(no detection guidance published)
Data sources
- (none listed)
References
- ATT&CK page: https://attack.mitre.org/techniques/T1567/001
- ATT&CK Enterprise matrix: https://attack.mitre.org/matrices/enterprise/