Files
splunk-security_content/stories/data_exfiltration.yml
2023-02-28 12:00:16 +01:00

24 lines
888 B
YAML

name: Data Exfiltration
id: 66b0fe0c-1351-11eb-adc1-0242ac120002
version: 1
date: '2020-10-21'
author: Shannon Davis, Splunk
description: The stealing of data by an adversary.
narrative: Exfiltration comes in many flavors. Adversaries can collect data over
encrypted or non-encrypted channels. They can utilise Command And Control channels
that are already in place to exfiltrate data. They can use both standard data transfer
protocols such as FTP, SCP, etc to exfiltrate data. Or they can use non-standard
protocols such as DNS, ICMP, etc with specially crafted fields to try and circumvent
security technologies in place.
references:
- https://attack.mitre.org/tactics/TA0010/
tags:
analytic_story: Data Exfiltration
category:
- Adversary Tactics
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
usecase: Advanced Threat Detection