MITRE ATT&CK technique
Exfiltration Over Web Service detection rulesT1567
Exfiltration Over Web Service (T1567) is a MITRE ATT&CK technique in the Exfiltration tactic. This page lists the 28 community-maintained Sigma detection rules in the library mapped to T1567 and its sub-techniques. Each rule includes its detection logic, log source, false positives and original YAML. These rules mainly target windows, linux, github.
Tactic
APT40 Dropbox Tool User Agent
highDetects suspicious user agent string of APT40 Dropbox tool
proxy
Communication To Ngrok Tunneling Service - Linux
highDetects an executable accessing an ngrok tunneling endpoint, which could be a sign of forbidden exfiltration of data exfiltration by malicious actors
linux · network_connection
Communication To Ngrok Tunneling Service Initiated
highDetects an executable initiating a network connection to "ngrok" tunneling domains. Attackers were seen using this "ngrok" in order to store their second stage payloads and malware. While communication with such domains can be legitimate, often times is a sign of either data exfiltration by malicious actors or additional download.
windows · network_connection
Curl File Upload To File Sharing Websites
highDetects usage of curl to upload files to known file sharing domains, which may indicate data exfiltration.
windows · process_creation
DNS Query for Anonfiles.com Domain - DNS Client
highDetects DNS queries for anonfiles.com, which is an anonymous file upload platform often used for malicious purposes
windows
DNS Query for Anonfiles.com Domain - Sysmon
highDetects DNS queries for "anonfiles.com", which is an anonymous file upload platform often used for malicious purposes
windows · dns_query
Monero Crypto Coin Mining Pool Lookup
highDetects suspicious DNS queries to Monero mining pools
dns
Process Initiated Network Connection To Ngrok Domain
highDetects an executable initiating a network connection to "ngrok" domains. Attackers were seen using this "ngrok" in order to store their second stage payloads and malware. While communication with such domains can be legitimate, often times is a sign of either data exfiltration by malicious actors or additional download.
windows · network_connection
PUA - Rclone Execution
highDetects execution of RClone utility for exfiltration as used by various ransomwares strains like REvil, Conti, FiveHands, etc
windows · process_creation
PUA - Restic Backup Tool Execution
highDetects the execution of the Restic backup tool, which can be used for data exfiltration. Threat actors may leverage Restic to back up and exfiltrate sensitive data to remote storage locations, including cloud services. If not legitimately used in the enterprise environment, its presence may indicate malicious activity.
windows · process_creation
Suspicious Dropbox API Usage
highDetects an executable that isn't dropbox but communicates with the Dropbox API
windows · network_connection
Arbitrary File Download Via ConfigSecurityPolicy.EXE
mediumDetects the execution of "ConfigSecurityPolicy.EXE", a binary part of Windows Defender used to manage settings in Windows Defender. Users can configure different pilot collections for each of the co-management workloads. It can be abused by attackers in order to upload or download files.
windows · process_creation
DNS Query To MEGA Hosting Website
mediumDetects DNS queries for subdomains related to MEGA sharing website
windows · dns_query
DNS Query To MEGA Hosting Website - DNS Client
mediumDetects DNS queries for subdomains related to MEGA sharing website
windows
LOLBAS Data Exfiltration by DataSvcUtil.exe
mediumDetects when a user performs data exfiltration by using DataSvcUtil.exe
windows · process_creation
Network Connection Initiated To BTunnels Domains
mediumDetects network connections to BTunnels domains initiated by a process on the system. Attackers can abuse that feature to establish a reverse shell or persistence on a machine.
windows · network_connection
Network Connection Initiated To Cloudflared Tunnels Domains
mediumDetects network connections to Cloudflared tunnels domains initiated by a process on the system. Attackers can abuse that feature to establish a reverse shell or persistence on a machine.
windows · network_connection
Network Connection Initiated To DevTunnels Domain
mediumDetects network connections to Devtunnels domains initiated by a process on a system. Attackers can abuse that feature to establish a reverse shell or persistence on a machine.
windows · network_connection
Network Connection Initiated To Visual Studio Code Tunnels Domain
mediumDetects network connections to Visual Studio Code tunnel domains initiated by a process on a system. Attackers can abuse that feature to establish a reverse shell or persistence on a machine.
windows · network_connection
Potential Data Exfiltration Via Curl.EXE
mediumDetects the execution of the "curl" process with "upload" flags. Which might indicate potential data exfiltration
windows · process_creation
Rclone Activity via Proxy
mediumDetects the use of rclone, a command-line program to manage files on cloud storage, via its default user-agent string
proxy
Rclone Config File Creation
mediumDetects Rclone config files being created
windows · file_event
Suspicious Curl File Upload - Linux
mediumDetects a suspicious curl process start the adds a file to a web request
linux · process_creation
Suspicious Non-Browser Network Communication With Telegram API
mediumDetects an a non-browser process interacting with the Telegram API which could indicate use of a covert C2
windows · network_connection
DNS Query To Ufile.io
lowDetects DNS queries to "ufile.io", which was seen abused by malware and threat actors as a method for data exfiltration
windows · dns_query
DNS Query To Ufile.io - DNS Client
lowDetects DNS queries to "ufile.io", which was seen abused by malware and threat actors as a method for data exfiltration
windows
GitHub Repository Pages Site Changed to Public
lowDetects when a GitHub Pages site of a repository is made public. This usually is part of a publishing process but could indicate or lead to potential unauthorized exposure of sensitive information or code.
github
Network Connection Initiated To Mega.nz
lowDetects a network connection initiated by a binary to "api.mega.co.nz". Attackers were seen abusing file sharing websites similar to "mega.nz" in order to upload/download additional payloads.
windows · network_connection