PurposeThe adversary is trying to steal data. Exfiltration consists of techniques that adversaries may use to steal data from your network. Once they’ve collected data, adversaries often package it to avoid detection while removing it. This can include compression and encryption. Techniques for getting data out of a target network typically include transferring it over their command and control channel or an alternate channel and may also include putting size limits on the transmission. | Included contentT1011: Exfiltration Over Other Network Medium T1020: Automated Exfiltration T1030: Data Transfer Size Limits T1048: Exfiltration Over Alternative Protocol T1052: Exfiltration over Physical Medium T1537: Transfer Data to Cloud Account T1567: Exfiltration over Web Service
| Prerequisites |