kevmap

Techniques › T1020

T1020 Automated Exfiltration

exfiltration — Linux, macOS, Network Devices, Windows · attack.mitre.org · JSON

1
MITRE detection strategy
3
analytics
10
Sigma rules tagged attack.t1020
0
KEV CVEs mapped here
<p>Adversaries may exfiltrate data, such as sensitive documents, through the use of automated processing after being gathered during Collection.</p><p>When automated exfiltration is used, other exfiltration techniques likely apply as well to transfer the information out of the network, such as Exfiltration Over C2 Channel and Exfiltration Over Alternative Protocol.</p>

KEV CVEs mapped to this technique · CTID Mappings Explorer

None. No KEV entry in the public mapping names this technique. Given that 74.7% of KEV has no mapping at all, this says more about the mapping than about the technique.

Detection strategy · ATT&CK Enterprise v19.2

Sigma rules · SigmaHQ da9bb07d64, tag attack.t1020

Author: Romain Gaillard (@romain-gaillard) · 2024-07-29 · logsource: product=github service=audit · 04ad83ef-1a37-4c10-b57a-81092164bf33
Detects when a repository or an organization is being transferred to another location.
Techniques: T1020T1537
Author: Nasreddine Bencherchali (Nextron Systems), Marco Pedrinazzi (@pedrinazziM) (InTheCyber) · 2026-03-01 · logsource: product=windows category=ps_script · 0c7686d5-c74e-4292-b224-2a08e956ebc4
Detects email forwarding or redirecting activity via ExchangePowerShell Cmdlet
Author: Ivan Saakov · 2024-12-06 · logsource: product=aws service=cloudtrail · 457cc9ac-d8e6-4d1d-8c0e-251d0f11a74c
Detects modifications to an RDS cluster or its deletion, which may indicate potential data exfiltration attempts, unauthorized access, or exposure of sensitive information.
Techniques: T1020
Author: Romain Gaillard (@romain-gaillard) · 2024-07-29 · logsource: product=github service=audit · 69b3bd1e-b38a-462f-9a23-fbdbf63d2294
Detects when the policy allowing forks of private and internal repositories is changed (enabled or cleared).
Techniques: T1020T1537
Author: Austin Songer @austinsonger · 2021-08-22 (modified 2022-10-09) · logsource: product=m365 service=threat_management · 6c220477-0b5b-4b25-bb90-66183b4089e8
Detects when a Microsoft Cloud App Security reported suspicious email forwarding rules, for example, if a user created an inbox rule that forwards a copy of all emails to an external address.
Techniques: T1020
Author: faloker · 2020-02-12 (modified 2022-10-05) · logsource: product=aws service=cloudtrail · 8a63cdd4-6207-414a-85bc-7e032bd3c1a2
Detects the change of database master password. It may be a part of data exfiltration.
Techniques: T1020
Author: faloker · 2020-02-12 (modified 2022-10-09) · logsource: product=aws service=cloudtrail · c3f265c7-ff03-4056-8ab2-d486227b4599
Detects the recovery of a new public database instance from a snapshot. It may be a part of data exfiltration.
Techniques: T1020
Author: RedCanary Team (idea), Harjot Singh @cyb3rjy0t · 2023-10-11 (modified 2024-11-17) · logsource: product=m365 service=audit · c726e007-2cd0-4a55-abfb-79730fbedee5
Detects email forwarding or redirecting activity in O365 Audit logs.
Author: frack113 · 2022-01-07 (modified 2025-07-18) · logsource: product=windows category=ps_script · d2e3f2f6-7e09-4bf2-bc5d-90186809e7fb
Detects PowerShell scripts leveraging the "Invoke-WebRequest" cmdlet to send data via either "PUT" or "POST" method.
Techniques: T1020
Author: Nasreddine Bencherchali (Nextron Systems) · 2023-05-05 · logsource: product=windows category=ps_script · fbc5e92f-3044-4e73-a5c6-1c4359b539de
Detects PowerShell scripts that have capabilities to read files, loop through them and resolve DNS host entries.
Techniques: T1020

Sub-techniques

IDNameSigma rulesKEV CVEs
T1020.001Traffic Duplication00