T1567.001: Exfiltration to Code Repository

exfiltration

Summary

Adversaries may exfiltrate data to a code repository rather than over their primary command and control channel. Code repositories are often accessible via an API (ex: https://api.github.com). Access to these APIs are often over HTTPS, which gives the adversary an additional level of protection. Exfiltration to a code repository can also provide a significant amount of cover to the adversary if it is a popular service already used by hosts within the network.

Source Attribution

Source: MITRE ATT&CK · Confidence: high

Platforms

  • ESXi
  • Linux
  • macOS
  • Windows

Tactic

exfiltration

References