Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Attack Patterns T1029 — Scheduled Transfer
T1029

Scheduled Transfer

Exfiltration
TLP:CLEAR

Description

Adversaries may schedule data exfiltration to be performed only at certain times of day or at certain intervals. This could be done to blend traffic patterns with normal activity or availability. When scheduled exfiltration is used, other exfiltration techniques likely apply as well to transfer the information out of the network, such as Exfiltration Over C2 Channel or Exfiltration Over Alternative Protocol.

MITRE ATT&CK Detection Strategies
1

DET0399 Detection Strategy for Scheduled Transfer and Recurrent Exfiltration Patterns
AN1119 Linux

Detection of cron-based or script-based recurring transfers where the same script, user, or destination reappears at predictable intervals.

auditd:SYSCALL linux:cron NSM:Flow
AN1118 Windows

Recurring network exfiltration initiated by scheduled or script-based processes exhibiting time-based regularity and consistent external destinations.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:System
AN1120 macOS

LaunchAgent or launchd recurring jobs initiating data transfer to consistent external IPs or domains with repeat timing signatures.

macos:endpointsecurity macos:launchd macos:unifiedlog

Details

Platforms
Linux
Macos
Windows
Added
May 2, 2026
Leaving Threaticon

This link opens an external site that isn't part of the platform.