ATT&CK · T1029
Scheduled Transfer
Tactics: exfiltration
About
Adversaries may schedule data exfiltration to be performed only at certain times of day or at certain intervals. This could be done to blend traffic patterns with normal activity or availability. When scheduled exfiltration is used, other exfiltration techniques likely apply as well to transfer the information out of the network, such as Exfiltration Over C2 Channel or Exfiltration Over Alternative Protocol.
Platforms: Linux, macOS, WindowsMITRE ATT&CK ↗
Used by actors
1 known groups
Software
17 malware/tools implement this
ADVSTORESHELLComRATCobalt StrikeDipsindLinfoPOWERSTATSKazuarjRATLightNeuronMacheteShimRatShadowPadChrommmeTinyTurlaFlagproSharkNinja
Corpus indicators tagged with this technique
0 indicators in the corpus carry T1029.
No corpus indicators are tagged with this technique yet.