Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Attack Patterns T1020 — Automated Exfiltration
T1020

Automated Exfiltration

Exfiltration
TLP:CLEAR

Description

Adversaries may exfiltrate data, such as sensitive documents, through the use of automated processing after being gathered during Collection.(Citation: ESET Gamaredon June 2020) When automated exfiltration is used, other exfiltration techniques likely apply as well to transfer the information out of the network, such as Exfiltration Over C2 Channel and Exfiltration Over Alternative Protocol.

MITRE ATT&CK Detection Strategies
1

DET0397 Automated Exfiltration Detection Strategy
AN1115 macOS

Observation of LaunchAgents or LaunchDaemons establishing periodic external connections indicative of automated data transfer.

macos:unifiedlog macos:unifiedlog macos:cron
AN1114 Linux

Background scripts (e.g., via cron) or daemons transmitting data repeatedly to remote IPs or URLs.

auditd:SYSCALL NSM:Flow
AN1113 Windows

Detection of automated tools or scripts periodically transmitting data to external destinations using scheduled tasks or background processes.

WinEventLog:Security WinEventLog:Sysmon

Details

Platforms
Linux
Macos
Network devices
Windows
Added
May 2, 2026
Leaving Threaticon

This link opens an external site that isn't part of the platform.