T1567.001 Exfiltration to Code Repository
Subtécnica de T1567 Exfiltration Over Web Service
Adversaries may exfiltrate data to a code repository rather than over their primary command and control channel. Code repositories are often accessible via an API (ex: https://api.github.com). Access to these APIs are often over HTTPS, which gives the adversary an additional level of protection. Exfiltration to a code repository can also provide a significant amount of cover to the adversary if…
Quién la usa · con noticias en Jábega
Reglas Sigma para cazarla
- Network Connection Initiated To DevTunnels Domainmediumtest · windows
Reglas de SigmaHQ · Detection Rule License 1.1. Técnica de MITRE ATT&CK®.