mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
1.9 KiB
1.9 KiB
title, last_modified_at, toc, tags
| title | last_modified_at | toc | tags | |||||
|---|---|---|---|---|---|---|---|---|
| Data Exfiltration | 2020-10-21 | true |
|
Description
The stealing of data by an adversary.
- ID: 66b0fe0c-1351-11eb-adc1-0242ac120002
- Product: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud
- Datamodel: Endpoint, Network_Traffic
- Last Updated: 2020-10-21
- Author: Shannon Davis, Splunk
Detection profiles
| Name | Technique | Type |
|---|---|---|
| DNS Exfiltration Using Nslookup App | None | TTP |
| Detect SNICat SNI Exfiltration | None | TTP |
| Detect shared ec2 snapshot | None | TTP |
| Excessive Usage of NSLOOKUP App | None | Anomaly |
| Mailsniper Invoke functions | None | TTP |
| Multiple Archive Files Http Post Traffic | None | TTP |
| O365 PST export alert | None | TTP |
| O365 Suspicious Admin Email Forwarding | None | Anomaly |
| O365 Suspicious User Email Forwarding | None | Anomaly |
| Plain HTTP POST Exfiltrated Data | None | TTP |
Reference
source | version: 1