Sub-technique of T1567 Exfiltration Over Web Service.View on attack.mitre.org
Adversaries may exfiltrate data to a code repository rather than over their primary command and control channel. Code repositories are often accessible via an API (ex: https://api.github.com). Access to these APIs are often over HTTPS, which gives the adversary an additional level of protection.
Exfiltration to a code repository can also provide a significant amount of cover to the adversary if it is a popular service already used by hosts within the network.
Rules on DetectionCode tagged with T1567.001.
| Rule | Level | Log source |
|---|---|---|
| Network Connection Initiated To DevTunnels Domain | medium | windows / network_connection |
| GitHub Repository Pages Site Changed to Public | low | github / NULL |
None recorded.
None recorded.
| Used by | Procedure example |
|---|---|
| ToolEmpire | Empire can use GitHub for data exfiltration. |
| MalwareMini Shai-Hulud | Mini Shai-Hulud has exfiltrated data through the use of the victim’s own GitHub repository by creating a new public repository using a unique naming convention from a curated list of key words or themes. |
| MalwareShai-Hulud | Shai-Hulud has created a repository named `Shai-Hulud` under the compromised account that commits a JSON dump that contains system information, environment variables and collected secrets. Shai-Hulud has also posted stolen credentials to public GitHub repositories. |
| MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can create a repository in the victim's GitHub account using the victim's own GITHUB_TOKEN to upload stolen credentials. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.