Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Exfiltration/ T1567.001

T1567.001Exfiltration to Code Repository

T1567.001 — Exfiltration to Code Repository is a MITRE ATT&CK technique in the Exfiltration tactic. Clankerusecase tracks 10 detection use cases covering it and 7 threat-intel articles citing it.

Exfiltration
View on the matrix → Filter Detection Library MITRE official spec ↗
10Use cases
7Articles
0Sub-techniques
1Tactic

Use cases covering this technique (10)

[WEEKLY] Developer interpreter / package-manager process exfiltrating tokens to public code-hosting / worker domains Internal install · alerting DSPDDCSCW [WEEKLY] Package manager spawns network-fetching child to public code-hosting within minutes of install Internal install · alerting DSPDD [WEEKLY] Script Interpreter or Package-Install Hook Egress to Free-Tier Edge SaaS Within 5 Minutes of Process Start Internal c2 · alerting DSΣPDD [LLM] npm lifecycle script harvests secrets via TruffleHog or chains to GitHub API Bespoke actions · alerting DSΣPDDCS [LLM] Node child of node-gyp/python making outbound to GitHub dead-drop or anomalous web service during install Bespoke exfil · hunting DSPDDCS [LLM] Public GitHub repo creation matching Miasma 'adjective-creature-N' exfil pattern Bespoke actions · hunting DSPDD [LLM] tj-actions/changed-files compromise: self-hosted runner egress to nikitastupin memdump gist (CVE-2025-30066) Bespoke delivery · hunting DSΣPDD [LLM] Shai-Hulud 3.0 'Goldox-T3chs' GitHub exfiltration marker observed Bespoke actions · alerting DSΣPDDCS [LLM] Bun/Node bursty PUT to api.github.com /contents from infected host (Sha1-Hulud exfil) Bespoke actions · alerting DSPDDCS [LLM] Node process creating GitHub repo via api.github.com (s1ngularity exfil channel) Bespoke actions · hunting DSPDDCS

Articles citing this technique (7)