Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Exfiltration/ T1020

T1020Automated Exfiltration

T1020 — Automated Exfiltration is a MITRE ATT&CK technique in the Exfiltration tactic. Clankerusecase tracks 4 detection use cases covering it and 2 threat-intel articles citing it.

Exfiltration
View on the matrix → Filter Detection Library MITRE official spec ↗
4Use cases
2Articles
1Sub-techniques
1Tactic

Sub-techniques (1)

Use cases covering this technique (4)

Detect RClone Command-Line Usage ESCU actions · alerting P Detect Renamed RClone ESCU actions · hunting P Windows Mustang Panda USB Tool Execution ESCU actions · alerting P [LLM] Multi-GB outbound transfer from single user to Tchap/Matrix endpoint (exfil volume) Bespoke actions · hunting DSPDDCS

Articles citing this technique (2)