mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
24 lines
888 B
YAML
24 lines
888 B
YAML
name: Data Exfiltration
|
|
id: 66b0fe0c-1351-11eb-adc1-0242ac120002
|
|
version: 1
|
|
date: '2020-10-21'
|
|
author: Shannon Davis, Splunk
|
|
description: The stealing of data by an adversary.
|
|
narrative: Exfiltration comes in many flavors. Adversaries can collect data over
|
|
encrypted or non-encrypted channels. They can utilise Command And Control channels
|
|
that are already in place to exfiltrate data. They can use both standard data transfer
|
|
protocols such as FTP, SCP, etc to exfiltrate data. Or they can use non-standard
|
|
protocols such as DNS, ICMP, etc with specially crafted fields to try and circumvent
|
|
security technologies in place.
|
|
references:
|
|
- https://attack.mitre.org/tactics/TA0010/
|
|
tags:
|
|
analytic_story: Data Exfiltration
|
|
category:
|
|
- Adversary Tactics
|
|
product:
|
|
- Splunk Enterprise
|
|
- Splunk Enterprise Security
|
|
- Splunk Cloud
|
|
usecase: Advanced Threat Detection
|