Scheduled Transfer T1029

Tactic: Exfiltration

Adversaries may schedule data exfiltration to be performed only at certain times of day or at certain intervals. This could be done to blend traffic patterns with normal activity or availability.

Events covered

3 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 3 rules share fields, values, and exclusions.

Fields filtered most (12 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
Action1is_not_null 1
BeaconPercent1ge 180.0
CommandLine1is_not_null 1
DbAction1eq 1connect
DeltaSec1gt 15
Dst1cross_field_compare 1NextDst
EventID1eq 14698, 4700, 4702
Proto1cross_field_compare 1NextProto
Src1cross_field_compare 1NextSrc
TotalFlows1ge 110
count1eq 11
src_ip1is_not_null 1

Top indicator values (11 distinct)

These values appear most often in rule predicates.

Exclusions (5 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
src_ipcidr_match
10.0.0.0/8
1
src_ipcidr_match
127.0.0.0/8
1
src_ipcidr_match
169.254.0.0/16
1
src_ipcidr_match
172.16.0.0/12
1
src_ipcidr_match
192.168.0.0/16
1

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Splunk 1 rule

Kusto 2 rules