Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Exfiltration/ T1020

T1020Automated Exfiltration

T1020 — Automated Exfiltration is a MITRE ATT&CK technique in the Exfiltration tactic. Clankerusecase tracks 4 detection use cases covering it and 3 threat-intel articles citing it.

Exfiltration
View on the matrix → Filter Detection Library MITRE official spec ↗
4Use cases
3Articles
1Sub-techniques
1Tactic

Sub-techniques (1)

Use cases covering this technique (4)

Detect RClone Command-Line Usage ESCU actions · alerting P Detect Renamed RClone ESCU actions · hunting P Windows Mustang Panda USB Tool Execution ESCU actions · alerting P [LLM] Malicious postmark-mcp BCC email exfiltration to phan@giftshop[.]club Bespoke actions · alerting DSP

Articles citing this technique (3)