Sigma Rule Library

MITRE ATT&CK technique

Automated Exfiltration detection rulesT1020

Automated Exfiltration (T1020) is a MITRE ATT&CK technique in the Exfiltration tactic. This page lists the 10 community-maintained Sigma detection rules in the library mapped to T1020 and its sub-techniques. Each rule includes its detection logic, log source, false positives and original YAML. These rules mainly target aws, windows, github.

Top products

Tactic