Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0397 — Automated Exfiltration Detection Strategy
DET0397

Automated Exfiltration Detection Strategy

3 analytic(s) · 1 technique(s) detected

Analytics

3
AN1113 Analytic 1113
Windows

Detection of automated tools or scripts periodically transmitting data to external destinations using scheduled tasks or background processes.

WinEventLog:Security EventCode=4688 WinEventLog:Sysmon EventCode=3, 22
[TimeWindow] Used to detect repeated exfil activity over intervals (e.g., every 5 minutes).
[DestinationIP] Can be tuned to filter known internal or trusted destinations.
AN1114 Analytic 1114
Linux

Background scripts (e.g., via cron) or daemons transmitting data repeatedly to remote IPs or URLs.

auditd:SYSCALL execve NSM:Flow Outbound Connections
[CronJobInterval] Tunable time range for recurring tasks seen creating outbound connections.
[UserContext] Tunable for scope — service accounts vs user accounts.
AN1115 Analytic 1115
macOS

Observation of LaunchAgents or LaunchDaemons establishing periodic external connections indicative of automated data transfer.

macos:unifiedlog process: exec macos:unifiedlog network macos:cron cron/launchd
[LaunchInterval] Frequency of task recurrence linked to external communication.
[DestinationPort] Port number used for detection filtering.

Detected Techniques

1

Details

MITRE ID
DET0397
STIX ID
x-mitre-detection-strategy--da5ff985-fd0d-438f-8498-c8dc195f741a
Analytics
3
Techniques Detected
1
By Tactic
Exfiltration
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.