Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Exfiltration/ T1567.002

T1567.002Exfiltration to Cloud Storage

T1567.002 — Exfiltration to Cloud Storage is a MITRE ATT&CK technique in the Exfiltration tactic. Clankerusecase tracks 29 detection use cases covering it and 21 threat-intel articles citing it.

Exfiltration
View on the matrix → Filter Detection Library MITRE official spec ↗
29Use cases
21Articles
0Sub-techniques
1Tactic

Use cases covering this technique (29)

Gsuite Drive Share In External Email ESCU actions · hunting P Cisco NVM - Rclone Execution With Network Activity ESCU actions · hunting P Windows Azure Storage Utility Execution Via CLI ESCU actions · hunting P Windows OneDrive Share Mounted via Net ESCU actions · hunting P Cisco Secure Firewall - Connection to File Sharing Domain ESCU actions · hunting P Cisco Secure Firewall - Potential Data Exfiltration ESCU actions · hunting P [LLM] HOLLOWGRAPH M365 calendar dead-drop: events dated 2050-05-13 via Graph API Bespoke c2 · hunting DSP [LLM] rclone cloud-exfiltration staging prior to Sinobi encryption Bespoke actions · alerting DSΣPDDCS [LLM] CI runner egress to Megalodon secret-exfil C2 216.126.225.129:8443 Bespoke actions · hunting DSΣPDDCS [LLM] Gamaredon stealer exfiltration to S3-compatible cloud storage (Wasabi/Tebi/Intercolo) Bespoke actions · alerting DSΣPDDCS [LLM] Klue/Icarus: bulk Salesforce CRM record retrieval via connected app (Case/Contact/Account/Opportunity) Bespoke actions · alerting DSP [LLM] Atomic Arch C2/exfil: build-spawned egress to temp.sh and github.com/fardewoak/nodejs-argo Bespoke c2 · alerting DSΣPDDCS [LLM] Shai-Hulud npm worm: secret exfiltration to hardcoded webhook.site endpoint Bespoke actions · alerting DSΣPDDCS [LLM] Shai-Hulud worm GitHub Action workflow file dropped under .github/workflows Bespoke install · alerting DSΣPDDCS [LLM] Megalodon harvester: curl POST to C2 /collect endpoint on Linux runner Bespoke actions · alerting DSΣPDDCS [LLM] Nx Console / Shai-Hulud C2 connection (t.m-kosche.com, check.git-service.com, filev2.getsession.org, api.masscan.cloud, 83.142.209.194) Bespoke c2 · alerting DSΣPDDCS [LLM] GitHub audit log bulk private-repo clone burst (post Nx Console compromise pattern) Bespoke actions · alerting DSPDD [LLM] GraphWorm OneDrive /createUploadSession C2 from non-Office process Bespoke c2 · hunting DSΣPDDCS [LLM] WormFrp / Webworm Amazon S3 staging bucket access (wamanharipethe / whpjewellers) Bespoke actions · alerting DSΣPDDCS [LLM] Mini Shai-Hulud dead-drop git commit authored as claude@users.noreply.github.com Bespoke actions · alerting DSΣPDDCS [LLM] BirdCall RokRAT cloud-storage C2 beacon (Dropbox/pCloud) from non-browser process Bespoke c2 · hunting DSPDDCS [LLM] Outbound upload to file.io from non-browser process (CompactGopher exfil) Bespoke actions · alerting DSΣPDDCS [LLM] TeamPCP Trivy/KICS C2 callback to scan.aquasecurtiy.org / 45.148.10.212 Bespoke c2 · hunting DSΣPDD [LLM] TeamPCP supply-chain C2 — outbound to checkmarx[.]zone / 83.142.209.11 Bespoke c2 · hunting DSΣPDD [LLM] TeamPCP exfiltration archive — tpcp.tar.gz file creation on host Bespoke actions · alerting DSΣPDD [LLM] Exfiltration to kubernetes-el attacker webhook.site UUIDs (Pwn Request payload) Bespoke c2 · alerting DSΣPDD [LLM] AI agent skill exfiltrates GitHub token / env secrets via dynamic-context shell-out Bespoke actions · alerting DSΣPDDCS [LLM] Moq SponsorLink email exfil egress to cdn.devlooped.com / SponsorLink blob Bespoke c2 · hunting DSΣPDDCS [LLM] Form-skimmer exfil to js-metrics.com (malicious angular-bmap / ng-ui-library npm versions) Bespoke actions · alerting DSΣPDDCS

Articles citing this technique (21)