{"id":"T1011","name":"Exfiltration Over Other Network Medium","url":"https://attack.mitre.org/techniques/T1011","tactics":["exfiltration"],"platforms":["Linux","macOS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0077","stix_id":"x-mitre-detection-strategy--9280a84d-bf77-4a86-a052-ce6ea0d50e72","name":"Detection of Exfiltration Over Alternate Network Interfaces","url":"https://attack.mitre.org/detectionstrategies/DET0077","analytics":[{"id":"AN0212","stix_id":"x-mitre-analytic--cf404364-1397-4f0f-9c21-cd534880722a","name":"Analytic 0212","description":"Execution of file transfer or network access activity through non-primary interfaces (e.g., WiFi, Bluetooth, cellular) by processes not typically associated with such behavior (e.g., rundll32, powershell, regsvr32).","url":"https://attack.mitre.org/detectionstrategies/DET0077#AN0212","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=3, 22","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:System","channel":"EventCode=5005 (WLAN), EventCode=302 (Bluetooth)","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"wineventlog-system"},{"name":"WinEventLog:Sysmon","channel":"EventCode=11","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"InterfaceType","description":"Filter for specific interface categories (e.g., WiFi, Bluetooth, 4G)."},{"field":"FileSizeThreshold","description":"Tunable for environment-specific large file access events pre-transfer."},{"field":"TimeWindow","description":"Temporal correlation window for file read followed by network activity."}],"live":true,"detection_strategies":["DET0077"],"techniques":["T1011"]},{"id":"AN0213","stix_id":"x-mitre-analytic--5b9f2d26-e84c-49a3-8586-a7367580b802","name":"Analytic 0213","description":"Use of `rfkill`, `nmcli`, or low-level tools (e.g., `iw`, `hcitool`, `pppd`) to enable alternate interfaces followed by data transfer via non-primary NICs.","url":"https://attack.mitre.org/detectionstrategies/DET0077#AN0213","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"None","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"auditd-syscall"},{"name":"NSM:Flow","channel":"None","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"CommandPattern","description":"Match known interface manipulation utilities or driver invocations."},{"field":"NetworkDevice","description":"Tunable to non-default or rarely used interfaces (e.g., wlan1, hci0)."}],"live":true,"detection_strategies":["DET0077"],"techniques":["T1011"]},{"id":"AN0214","stix_id":"x-mitre-analytic--5a05483c-fb3b-4240-bf90-c1873b6bd392","name":"Analytic 0214","description":"AppleScript or system calls to activate WiFi/Bluetooth interfaces (`networksetup`, `blueutil`), followed by exfiltration via AirDrop, cloud sync, or network socket.","url":"https://attack.mitre.org/detectionstrategies/DET0077#AN0214","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"None","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"macos-unifiedlog"},{"name":"macos:osquery","channel":"process_events","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-osquery"},{"name":"macos:osquery","channel":"interface_details ","data_component":"DC0018","data_component_name":"Host Status","log_source_slug":"macos-osquery"}],"mutable_elements":[{"field":"Protocol","description":"Protocol used for exfil (e.g., AirDrop, mDNS, Apple File Service)."},{"field":"InterfaceActivityWindow","description":"Time period between interface activation and transfer."}],"live":true,"detection_strategies":["DET0077"],"techniques":["T1011"]}],"live":true,"version":"1.0","techniques":["T1011"]}],"sigma_rules":[],"kev_cves":[{"cveID":"CVE-2024-53150","state":"mapped","mapping_types":["secondary_impact"]},{"cveID":"CVE-2024-50302","state":"mapped","mapping_types":["secondary_impact"]},{"cveID":"CVE-2024-40891","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2024-40890","state":"mapped","mapping_types":["primary_impact"]}],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}