Techniques › T1020
T1020 Automated Exfiltration
exfiltration — Linux, macOS, Network Devices, Windows · attack.mitre.org · JSON
1
MITRE detection strategy
3
analytics
10
Sigma rules tagged attack.t1020
0
KEV CVEs mapped here
<p>Adversaries may exfiltrate data, such as sensitive documents, through the use of automated processing after being gathered during Collection.</p><p>When automated exfiltration is used, other exfiltration techniques likely apply as well to transfer the information out of the network, such as Exfiltration Over C2 Channel and Exfiltration Over Alternative Protocol.</p>
KEV CVEs mapped to this technique · CTID Mappings Explorer
None. No KEV entry in the public mapping names this technique. Given that 74.7% of KEV has no mapping at all, this says more about the mapping than about the technique.
Detection strategy · ATT&CK Enterprise v19.2
- DET0397 Automated Exfiltration Detection Strategy v1.0
AN1113 WindowsDetection of automated tools or scripts periodically transmitting data to external destinations using scheduled tasks or background processes.Tunable:
TimeWindowDestinationIPAN1114 LinuxBackground scripts (e.g., via cron) or daemons transmitting data repeatedly to remote IPs or URLs.Tunable:CronJobIntervalUserContextAN1115 macOSObservation of LaunchAgents or LaunchDaemons establishing periodic external connections indicative of automated data transfer.Tunable:LaunchIntervalDestinationPort
Sigma rules · SigmaHQ da9bb07d64, tag attack.t1020
Author: Romain Gaillard (@romain-gaillard)
· 2024-07-29 · logsource: product=github service=audit · 04ad83ef-1a37-4c10-b57a-81092164bf33
Detects when a repository or an organization is being transferred to another location.
Author: Nasreddine Bencherchali (Nextron Systems), Marco Pedrinazzi (@pedrinazziM) (InTheCyber)
· 2026-03-01 · logsource: product=windows category=ps_script · 0c7686d5-c74e-4292-b224-2a08e956ebc4
Detects email forwarding or redirecting activity via ExchangePowerShell Cmdlet
Author: Ivan Saakov
· 2024-12-06 · logsource: product=aws service=cloudtrail · 457cc9ac-d8e6-4d1d-8c0e-251d0f11a74c
Detects modifications to an RDS cluster or its deletion, which may indicate potential data exfiltration attempts, unauthorized access, or exposure of sensitive information.
Author: Romain Gaillard (@romain-gaillard)
· 2024-07-29 · logsource: product=github service=audit · 69b3bd1e-b38a-462f-9a23-fbdbf63d2294
Detects when the policy allowing forks of private and internal repositories is changed (enabled or cleared).
Author: Austin Songer @austinsonger
· 2021-08-22 (modified 2022-10-09) · logsource: product=m365 service=threat_management · 6c220477-0b5b-4b25-bb90-66183b4089e8
Detects when a Microsoft Cloud App Security reported suspicious email forwarding rules, for example, if a user created an inbox rule that forwards a copy of all emails to an external address.
Author: faloker
· 2020-02-12 (modified 2022-10-05) · logsource: product=aws service=cloudtrail · 8a63cdd4-6207-414a-85bc-7e032bd3c1a2
Detects the change of database master password. It may be a part of data exfiltration.
Author: faloker
· 2020-02-12 (modified 2022-10-09) · logsource: product=aws service=cloudtrail · c3f265c7-ff03-4056-8ab2-d486227b4599
Detects the recovery of a new public database instance from a snapshot. It may be a part of data exfiltration.
Author: RedCanary Team (idea), Harjot Singh @cyb3rjy0t
· 2023-10-11 (modified 2024-11-17) · logsource: product=m365 service=audit · c726e007-2cd0-4a55-abfb-79730fbedee5
Detects email forwarding or redirecting activity in O365 Audit logs.
Author: frack113
· 2022-01-07 (modified 2025-07-18) · logsource: product=windows category=ps_script · d2e3f2f6-7e09-4bf2-bc5d-90186809e7fb
Detects PowerShell scripts leveraging the "Invoke-WebRequest" cmdlet to send data via either "PUT" or "POST" method.
Author: Nasreddine Bencherchali (Nextron Systems)
· 2023-05-05 · logsource: product=windows category=ps_script · fbc5e92f-3044-4e73-a5c6-1c4359b539de
Detects PowerShell scripts that have capabilities to read files, loop through them and resolve DNS host entries.
Sub-techniques
| ID | Name | Sigma rules | KEV CVEs |
|---|---|---|---|
| T1020.001 | Traffic Duplication | 0 | 0 |