FORENSIA

ATT&CK · T1567

Exfiltration Over Web Service

Tactics: exfiltration

About

Adversaries may use an existing, legitimate external Web service to exfiltrate data rather than their primary command and control channel. Popular Web services acting as an exfiltration mechanism may give a significant amount of cover due to the likelihood that hosts within a network are already communicating with them prior to compromise. Firewall rules may also already exist to permit traffic to these services. Web service providers also commonly use SSL/TLS encryption, giving adversaries an added level of protection.

Platforms: ESXi, Linux, macOS, Office Suite, SaaS, WindowsMITRE ATT&CK ↗

Used by actors

4 known groups

Software

7 malware/tools implement this

ngrokDropBookAppleSeedSampleCheck5000OilCheckExbyteInvisibleFerret

Corpus indicators tagged with this technique

310 indicators in the corpus carry T1567.

IndicatorTypeFamilySevSrc
cve-2025-1055cveransomware853
cve-2023-52271cveransomware853
cve-2025-61155cveransomware853
4a1a6ed11fd50b621659d7976899d050ba2e15d3hash801
74bb6ad7e1310f30a3e24fd3cbbffa2c0c41c64e89e5d0dd1d6900e96b914183hash801
1898d056463284d849801cbdea6a3dec6c9f568f01569912c3868a5eea9a5449hashransomware801
523388567630e4fbdc359f75232bf2ad82671a680d4bfdce0237fc30dfec4c80hash801
449e4265979b5fdb2d3446c021af437e815debd66de7da2fe54f1ad93cbcc75ehashsupply_chain801
f4d4b8cac004bb63834c6df436721babd9464c09787c80b268d839e0aada9f87hash801
442e0f4e822842922e7e4685840194e99fd68c7f0ec38c1925914b8f724d5865hash801
97aebda5482899fef84a24e456bff055acaa47e5ab4029f768d9e0c62a660ce2hashransomware801
90e46e89fec2108a1cb4850bb33e3563e92a14d04e1e613ac8c9311f152d294chashransomware801
dc9938f51150d13a69fc25f3f19052eacb1bf0a086fd5cf39762501fb3ddd7dahashransomware801
4eebc38297a307d18784d6f9ebc8aa6e6f69860be970cc70d9e544deb1ff6ce0hash801
03dd0efa84d145d7d4ed8e240267e5c5hashransomware801
6bf155b269d452f3c3b62832b27bbebe4da436e228dbf521155b1d5989e3743fhashransomware801
1d10d8f5a420d0e4683b4cb40bcf0c984d1e7ea1f3b4442a00a525584632ac11hashransomware801
16bad42a397db2e075e09b5b9dd53aaa67b495a4hashransomware801
78a82d93b4f580835f5823b85a3d9ee1f03a15ee6f0e01b4eac86252a7002981hashsupply_chain801
5cc212f84d2bf3fbab165aaf09b16e00fcf2f1ccd880d24b14404c53dcdbf241hashransomware801
24f6c0ca39b2a5593086ff56d818ddfbde121f8e44d54faa762e510397dc9db7hashransomware801
31800380c359143ae82c4f9011eee653dd22443d03d6a499148203bbfc275502hashransomware801
6cd349eda0fa6c8b274a0920852c68f8b727afea1fdbc69ad183cef05d9cf141hashransomware801
6f9fbe29f8cc2788e2bc9d631e0eea2a8e9837076837b55838005a0e654f0a9ehashransomware803
7f37351979c249417cb180b4ede0ed17e5fe2a1f08add4d72606b589f8fdb245hashransomware801
8d1a22c430252f29611766b8e4a82af0fba60d609246463466b384d6d4793df4hashransomware801
686213cc11d36af764de824801bced9366dfca3823fe0d51b752f74149bcf1f4sha256ransomware801
bf8c45e5aa9551a17eefbd1d179422c32b4309c47ee9a3f315bb80ed6d4f7efchashransomware801
f6a01d0246ce31faf6938ea488086d4358505405a4ef5c5faa482e79e92cb347hashransomware801
265a8e89464e32b22553ef16edbab703da7176a7hashransomware801

Showing the top 30 by severity of 310.