T1567.002 — Exfiltration to Cloud Storage
T1567.002: Exfiltration to Cloud Storage
MITRE ATT&CK® Enterprise technique
| Tactics | Exfiltration |
| Platforms | ESXi, Linux, macOS, Windows |
| Permissions required | — |
| Version | 1.3 |
| Parent technique | T1567 |
Description
Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel. Cloud storage services allow for the storage, edit, and retrieval of data from a remote cloud storage server over the Internet.
Examples of cloud storage services include Dropbox and Google Docs. Exfiltration to these cloud storage services can provide a significant amount of cover to the adversary if hosts within the network are already communicating with the service.
Detection
(no detection guidance published)
Data sources
- (none listed)
References
- ATT&CK page: https://attack.mitre.org/techniques/T1567/002
- ATT&CK Enterprise matrix: https://attack.mitre.org/matrices/enterprise/