{"id":"T1567.003","name":"Exfiltration to Text Storage Sites","url":"https://attack.mitre.org/techniques/T1567/003","tactics":["exfiltration"],"platforms":["Linux","macOS","Windows","ESXi"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0284","stix_id":"x-mitre-detection-strategy--6ab41bc0-2d89-4173-8149-728fbc2698b6","name":"Detection Strategy for Exfiltration to Text Storage Sites","url":"https://attack.mitre.org/detectionstrategies/DET0284","analytics":[{"id":"AN0787","stix_id":"x-mitre-analytic--4e8da615-4d12-4b53-8c7b-06d7c41e22a9","name":"Analytic 0787","description":"Unexpected processes (e.g., powershell.exe, wscript.exe, office apps) initiating HTTP POST/PUT requests to text storage domains like pastebin.com or hastebin.com, particularly when preceded by file access in sensitive directories. Defender perspective: correlation of process lineage, large clipboard/file read operations, and outbound uploads to text storage services.","url":"https://attack.mitre.org/detectionstrategies/DET0284#AN0787","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4663, 4670, 4656","data_component":"DC0055","data_component_name":"File Access","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Sysmon","channel":"EventCode=3, 22","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"TextStorageDomains","description":"Domains to monitor such as pastebin.com, hastebin.com, ghostbin.com."},{"field":"UploadSizeThreshold","description":"Minimum data size (e.g., >500KB) to trigger alerts for suspicious uploads."},{"field":"UserContext","description":"User accounts with legitimate business justification for posting to text storage sites."}],"live":true,"detection_strategies":["DET0284"],"techniques":["T1567.003"]},{"id":"AN0788","stix_id":"x-mitre-analytic--dd202a3f-c73b-47cf-9689-f14a8def816e","name":"Analytic 0788","description":"Use of curl, wget, or custom scripts to POST data to pastebin-like services. Defender perspective: identify chained behavior where files are compressed/read followed by HTTPS POST requests to text-sharing endpoints.","url":"https://attack.mitre.org/detectionstrategies/DET0284#AN0788","platforms":["Linux"],"log_source_references":[{"name":"auditd:EXECVE","channel":"curl -d, wget --post-data","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"auditd-execve"},{"name":"auditd:SYSCALL","channel":"read/open of sensitive file directories","data_component":"DC0055","data_component_name":"File Access","log_source_slug":"auditd-syscall"},{"name":"NSM:Flow","channel":"large HTTPS POST requests to text storage domains","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"AllowedTools","description":"Whitelist of tools (e.g., curl for package repos) to reduce false positives."},{"field":"WorkHours","description":"Expected time ranges for developer interactions with external paste sites."}],"live":true,"detection_strategies":["DET0284"],"techniques":["T1567.003"]},{"id":"AN0789","stix_id":"x-mitre-analytic--cf74f802-0080-41ff-8745-9c42af313462","name":"Analytic 0789","description":"Processes such as osascript, curl, or office applications sending data to text storage APIs/domains. Defender perspective: anomalous clipboard or file reads by unexpected applications immediately followed by outbound HTTPS requests to pastebin-like services.","url":"https://attack.mitre.org/detectionstrategies/DET0284#AN0789","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"execution of curl, osascript, or unexpected Office processes","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"file read of sensitive directories","data_component":"DC0055","data_component_name":"File Access","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"HTTPS POST requests to pastebin.com or similar","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"WatchedApps","description":"Processes not normally associated with data uploads (e.g., Preview, Calculator)."},{"field":"EntropyThreshold","description":"High entropy detection to flag encoded or encrypted data exfiltration."}],"live":true,"detection_strategies":["DET0284"],"techniques":["T1567.003"]},{"id":"AN0790","stix_id":"x-mitre-analytic--58a609cb-b266-4a1a-a40f-9e4cd5d591ce","name":"Analytic 0790","description":"ESXi services (vmx, hostd) generating outbound HTTPS POST requests to text storage sites. Defender perspective: anomalous datastore or log reads chained with traffic to pastebin-like destinations.","url":"https://attack.mitre.org/detectionstrategies/DET0284#AN0790","platforms":["ESXi"],"log_source_references":[{"name":"esxi:hostd","channel":"datastore/log file access","data_component":"DC0055","data_component_name":"File Access","log_source_slug":"esxi-hostd"},{"name":"esxi:vmkernel","channel":"HTTPS POST connections to pastebin-like domains","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"esxi-vmkernel"}],"mutable_elements":[{"field":"DatastoreExfilThreshold","description":"Threshold of bytes exfiltrated from ESXi datastore files."},{"field":"ApprovedDestinations","description":"Whitelist of domains approved for API communication to prevent false positives."}],"live":true,"detection_strategies":["DET0284"],"techniques":["T1567.003"]}],"live":true,"version":"1.0","techniques":["T1567.003"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}