Umbra Wiki technique technique/T1567.001
Back to wiki

T1567.001 — Exfiltration to Code Repository

provenance: imported · ATT&CK: T1567.001

T1567.001: Exfiltration to Code Repository

MITRE ATT&CK® Enterprise technique

Tactics Exfiltration
Platforms ESXi, Linux, macOS, Windows
Permissions required
Version 1.2
Parent technique T1567

Description

Adversaries may exfiltrate data to a code repository rather than over their primary command and control channel. Code repositories are often accessible via an API (ex: https://api.github.com). Access to these APIs are often over HTTPS, which gives the adversary an additional level of protection.

Exfiltration to a code repository can also provide a significant amount of cover to the adversary if it is a popular service already used by hosts within the network.

Detection

(no detection guidance published)

Data sources

  • (none listed)

References

  • ATT&CK page: https://attack.mitre.org/techniques/T1567/001
  • ATT&CK Enterprise matrix: https://attack.mitre.org/matrices/enterprise/