Umbra Wiki technique technique/T1567.002
Back to wiki

T1567.002 — Exfiltration to Cloud Storage

provenance: imported · ATT&CK: T1567.002

T1567.002: Exfiltration to Cloud Storage

MITRE ATT&CK® Enterprise technique

Tactics Exfiltration
Platforms ESXi, Linux, macOS, Windows
Permissions required
Version 1.3
Parent technique T1567

Description

Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel. Cloud storage services allow for the storage, edit, and retrieval of data from a remote cloud storage server over the Internet.

Examples of cloud storage services include Dropbox and Google Docs. Exfiltration to these cloud storage services can provide a significant amount of cover to the adversary if hosts within the network are already communicating with the service.

Detection

(no detection guidance published)

Data sources

  • (none listed)

References

  • ATT&CK page: https://attack.mitre.org/techniques/T1567/002
  • ATT&CK Enterprise matrix: https://attack.mitre.org/matrices/enterprise/