Automated Exfiltration T1020

Tactic: Exfiltration

Adversaries may exfiltrate data, such as sensitive documents, through the use of automated processing after being gathered during Collection.

Events covered

4 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 53 rules share fields, values, and exclusions.

Fields filtered most (67 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
EventType9eq 8, contains 1createtrafficmirrorsession, filedownloaded, git.clone, protected_branch.policy_override, protected_branch.rejected_ref_update
action7eq 5, starts_with 2hook., domain_breached, email_breached, migration.create, org.transfer
aws::eventSource7eq 7rds.amazonaws.com, SharePoint, securitycompliancecenter
data_stream.dataset7eq 7github.audit, aws.cloudtrail, o365.audit
m365::Workload6eq 4, contains 2Exchange, exchange, onedrive, sharepoint
Operation5contains 3, in 2filedownloaded, filesyncdownloadedfull, filesyncuploadedfull, new-transportrule, set-transportrule
aws::eventName5eq 5RestoreDBInstanceFromDBSnapshot, deletedbcluster, modifydbcluster, modifydbinstance, restoredbinstancefromdbsnapshot
process_name5contains 2, eq 1, ne 1, regex_match 1rclone.exe, sftp, (?i)\w+\.(exe)
CommandLine4regex_match 3, in 1(?i)\w+\.(bat|ps1|sh), *--auto-confirm*, *--config*, *--ignore-existing*
EventID4eq 40, 1, 4688
github.category4eq 4protected_branch, pull_request, repo
ScriptBlockText3contains 3, match 1-method "post", -method "put", -method 'post', [system.net.dns]::gethostentry, foreach
event.type3eq 3change
event_type3eq 3breach, item_access
m365::Parameters3contains 3forwardingsmtpaddress, forwardto, redirectto, forwardasattachmentto, forwardingaddress

Top indicator values (240 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
data_stream.dataseteq
github.audit
518
aws::eventSourceeq
rds.amazonaws.com
423
aws::eventSourceeq
SharePoint
22
CommandLineregex_match
(?i)\w+\.(bat|ps1|sh)
33
event.typeeq
change
394
m365::Parameterscontains
forwardingsmtpaddress
33
m365::Parameterscontains
forwardto
33
m365::Parameterscontains
redirectto
33
DistinctUserCountgt
1
22
EventIDeq
0
22
EventLogeq
Application
22
Operationcontains
filedownloaded
22
Operationcontains
filesyncdownloadedfull
22
Operationcontains
filesyncuploadedfull
22
Operationcontains
fileuploaded
22
Operationin
new-transportrule
22
Operationin
set-transportrule
24
OriginalFileNameeq
rclone.exe
23
RenderedDescriptioncontains
downloaded
22
RenderedDescriptioncontains
uploaded
22
SyslogMessagecontains
bytes read
22
SyslogMessagecontains
close
22
SyslogMessagecontains
session opened for
22
UserOrientedeq
yes
22
actionstarts_with
hook.
22
event.outcomeeq
success
2369
event_typeeq
breach
22
github.categoryeq
protected_branch
24
m365::Workloadcontains
onedrive
22
m365::Workloadcontains
sharepoint
22

Exclusions (6 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
AADEmaileq
[]
1
Imagestarts_with
c:\\
1
m365::ApplicationIdin
08e18876-6177-487e-b8b5-cf950c1e598c
1
m365::ApplicationIdin
7ab7862c-4c57-491e-8a45-d52a7e023983
1
m365::ApplicationIdin
d3590ed6-52b3-4102-aeff-aad2292ab01c
1
m365::ApplicationIdin
fb8d773d-7ef8-4ec0-a117-179f88add510
1

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 10 rules

Elastic 7 rules

Splunk 7 rules

Kusto 23 rules

Panther 6 rules