Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Exfiltration/ T1567

T1567Exfiltration Over Web Service

T1567 — Exfiltration Over Web Service is a MITRE ATT&CK technique in the Exfiltration tactic. Clankerusecase tracks 71 detection use cases covering it and 49 threat-intel articles citing it.

Exfiltration
View on the matrix → Filter Detection Library MITRE official spec ↗
71Use cases
49Articles
4Sub-techniques
1Tactic

Sub-techniques (4)

Use cases covering this technique (71)

Application data exfiltration successful Internal actions · alerting DD [WEEKLY] Install-Triggered Registry Publish or Git Push (Supply-Chain Worm Self-Propagation) Internal actions · alerting DSPDDCSCW [WEEKLY] Non-Browser Process Reads Browser Credential / Cookie SQLite Then Egresses to Public Destination Within 10 Minutes Internal actions · alerting DSPDD [WEEKLY] npm Install-Time Lifecycle Hook Triggers Outbound Egress to Newly-Seen Domain (Shai-Hulud/Miasma/IronWorm pattern) Internal install · alerting DSPDD [WEEKLY] Package-manager child process credential fan-out with public egress (Mini Shai-Hulud / TeamPCP worm chain) Internal install · alerting DSPDD [WEEKLY] Package-Manager Install -> Interpreter Child -> Non-Registry Egress Within 5 Minutes Internal install · alerting DSPDD [WEEKLY] Package-manager install-time interpreter spawn with credential-file read and outbound egress within 120s Internal install · alerting DSPDD [WEEKLY] Supply-chain repo credential theft → outbound exfil to attacker infra Internal actions · alerting DSPDD O365 DLP Rule Triggered ESCU actions · hunting P O365 Email Access By Security Administrator ESCU actions · alerting P O365 Exfiltration via File Access ESCU actions · hunting P O365 Exfiltration via File Download ESCU actions · hunting P O365 Exfiltration via File Sync Download ESCU actions · hunting P Linux Gdrive Binary Activity ESCU actions · alerting P LOLBAS With Network Traffic ESCU actions · alerting P Windows Gdrive Binary Activity ESCU actions · alerting P Cisco TFTP Server Configuration for Data Exfiltration ESCU actions · alerting P High Volume of Bytes Out to Url ESCU actions · hunting P Splunk Data exfiltration from Analytics Workspace using sid query ESCU actions · hunting P [LLM] Bulk M365 / SharePoint / OneDrive file download by a single identity (cloud data theft) Bespoke actions · alerting DSP [LLM] TELESHIM/MIXEDKEY sideload host binary beacons to Telegram (C2 + exfil) Bespoke actions · alerting DSΣPDDCS [LLM] InsureOTP kit exfiltration: browser connecting to api.telegram.org Bot API Bespoke actions · alerting DSΣPDDCS [LLM] Budibase server leaks datasource auth to first-seen host (undici + Authorization egress) Bespoke actions · hunting SP [LLM] macOS BlueNoroff stealer exfiltrating to Telegram bot (Aurora channel) Bespoke actions · alerting DSΣPCS [LLM] Network egress from CI/build host to GhostAction secret-exfil infrastructure Bespoke c2 · hunting DSΣPDDCS [LLM] CI runner process POSTing secrets to GhostAction exfil host via curl/wget/node Bespoke actions · alerting DSΣPDDCS [LLM] Shai-Hulud credential exfiltration: node/npm outbound to webhook.site Bespoke actions · alerting DSΣPDDCS [LLM] Injective SDK wallet-key exfil to lookalike domain testnet.archival.chain.grpc-web.injective.network Bespoke actions · alerting DSΣPDDCS [LLM] CVE-2026-50027 unauthenticated bulk read/enumeration of mcp-memory-service document store Bespoke actions · alerting SP [LLM] First-seen external egress from GitHub Actions Runner.Worker child process Bespoke actions · hunting DSPCS [LLM] Developer-runtime exfiltration to webhook.site (Shai-Hulud token drop) Bespoke actions · alerting DSΣPDDCS [LLM] Exfiltration to attacker-controlled Sentry ingest endpoint (onering crate) Bespoke actions · alerting DSΣPDDCS [LLM] Rust build script making outbound network connection (build-time exfil) Bespoke c2 · hunting DSΣPDDCS [LLM] node child of npm install initiating outbound network to non-registry destination Bespoke c2 · hunting DSPDDCS [LLM] Mini Shai-Hulud npm worm exfil to filev2.getsession.org Bespoke actions · alerting DSPDDCS [LLM] postmark-mcp BCC exfil to giftshop.club Bespoke actions · alerting DSΣPDDCS [LLM] DNS/HTTPS exfil to sentry.anyclaw.store (Codex token C2 masquerading as Sentry) Bespoke c2 · alerting DSΣPDDCS [LLM] Mini Shai-Hulud npm worm C2/exfil egress (masscan.cloud, git-tanstack.com, getsession.org) Bespoke actions · alerting DSΣPDDCS [LLM] Megalodon CI/CD exfil: outbound HTTPS to C2 216.126.225.129:8443 Bespoke c2 · hunting DSΣPDDCS [LLM] DNS / Network egress to TeamPCP Nx Console C2 domain check.git-service.com Bespoke c2 · alerting DSΣPDDCS [LLM] Outbound C2 to t.m-kosche.com from CI/CD runner or any endpoint Bespoke c2 · alerting DSΣPDDCS [LLM] Mini Shai-Hulud GitHub dead-drop exfiltration via python-requests/2.31.0 Bespoke actions · hunting DSΣPDDCS [LLM] Mini Shai-Hulud npm Worm C2 callback to Session Protocol CDN and masscan.cloud Bespoke c2 · alerting DSΣPDDCS [LLM] Shai-Hulud style repository poisoning — .claude/router_runtime.js drop Bespoke actions · alerting DSΣPDD [LLM] Mini Shai-Hulud 'OhNoWhatsGoingOnWithGitHub' dead-drop keyword in outbound URL Bespoke c2 · alerting DSΣPDD [LLM] Svix Ingest webhook exfiltration relay (src_3387PLMB2uhXOBe3Q8sHu) Bespoke exfiltration · alerting DSΣPDDCS [LLM] Mini Shai-Hulud post-compromise persistence artifacts in .claude/, .vscode/, .github/workflows/ Bespoke actions · alerting DSΣPDD [LLM] Exfil to skyhanni.cloud C2 with X-Rise-To-The-Trinny header Bespoke c2 · alerting DSΣPDDCS [LLM] Suspicious draft email manipulation against barrantaya.1010@outlook.com (BoxOfFriends Graph API C2) Bespoke c2 · hunting DSPDDCS [LLM] Shai-Hulud preinstall: node/npm spawning git/curl/gh pushing to attacker repo or GitHub API Bespoke actions · hunting DSPDDCS [LLM] hackerbot-claw payload host: DNS/HTTP egress to hackmoltrepeat.com (C2 + exfil) Bespoke c2 · alerting DSΣPDDCS [LLM] hackerbot-claw token exfiltration: curl POST with GITHUB_TOKEN to recv.hackmoltrepeat.com Bespoke actions · alerting DSΣPDDCS [LLM] TeamPCP tpcp.tar.gz exfil POST signature on egress proxy / WAF Bespoke actions · alerting DSΣPDDCS [LLM] Trivy supply-chain C2 beacon to typosquat domain scan.aquasecurtiy.org Bespoke c2 · alerting DSΣPDD [LLM] DNS tunneling exfiltration pattern to *.t.opentensor-cdn.com (hex chunk/index/total/session) Bespoke c2 · alerting DSΣPDD [LLM] C2 beaconing to Vercel-hosted Cloudflare-impersonating domains (cloudflareguard / cloudflareinsights) Bespoke c2 · alerting DSΣPDD [LLM] Outbound traffic to *.oastify.com (BurpSuite Collaborator) from corporate endpoint Bespoke exfiltration · alerting DSΣPDDCS [LLM] Egress to Qix npm phishing/exfil infrastructure (npmjs.help, publicvm.com, BunnyCDN buckets) Bespoke c2 · hunting DSΣPDDCS [LLM] GhostChat C2 beacon URL pattern: hitpak.org/page.php?tynor=<host>sss<user> Bespoke exfil · alerting DSΣPDDCS [LLM] Nx s1ngularity exfiltration via public GitHub repo 's1ngularity-repository' Bespoke actions · alerting DSΣPDDCS [LLM] Shai-Hulud 3.0 'Goldox-T3chs' GitHub exfiltration marker observed Bespoke actions · alerting DSΣPDDCS [LLM] Outbound exfiltration to webhook.site from npm / node / bun process tree Bespoke c2 · alerting DSΣPDDCS [LLM] Outbound email BCC'd to giftshop.club exfil domain (postmark-mcp backdoor) Bespoke actions · alerting DSΣPDD [LLM] DNS or HTTP egress to giftshop.club exfil domain Bespoke c2 · alerting DSΣPDDCS [LLM] Shai-Hulud worm C2 exfiltration to webhook.site UUID bb8ca5f6 Bespoke c2 · alerting DSΣPDDCS [LLM] Egress to websocket-api2.publicvm.com (Qix campaign credential exfil C2) Bespoke c2 · alerting DSΣPDDCS [LLM] Discord webhook / CDN exfiltration from non-browser process (Empyrean stealer C2) Bespoke actions · hunting DSPDDCS [LLM] npm dropper exfiltration to pkgio.com telemetry server Bespoke exfil · alerting DSΣPDDCS [LLM] SourMint/Mintegral SDK covert click-data exfiltration to n.systemlog.me Bespoke actions · alerting DSΣPCS [LLM] Agama wallet C2/exfil callback to updatecheck.herokuapp.com (electron-native-notify) Bespoke c2 · alerting DSΣPDDCS [LLM] Copay wallet-stealer C2 exfil to copayapi.host / 111.90.151.134 Bespoke c2 · hunting DSΣPDDCS

Articles citing this technique (49)