Exfiltration Detection Rules
The adversary is trying to steal data. Exfiltration consists of techniques that adversaries may use to steal data from your network. Once they’ve collected data, adversaries often package it to avoid detection while removing it. This can include compression and encryption. Techniques for getting data out of a target network typically include transferring it over their command and control channel or an alternate channel and may also include putting size limits on the transmission.
df00tech ships 50 production-ready detection rules mapped to the Exfiltration tactic (TA0010). Each rule below includes copy-paste queries for Microsoft Sentinel (KQL), Splunk (SPL), Elastic (EQL), QRadar, Sumo Logic, Chronicle and LogScale, with data-source requirements, severity and false-positive guidance — free to use.
Unlock the full Pro package
Response playbooks, investigation guides and atomic tests for every technique — from £29/mo.
Exfiltration detections (50)
- CVE-2025-11371 Gladinet CentreStack/Triofox Unauthorized File/Directory Access (CVE-2025-11371)
- CVE-2026-0755 CVE-2026-0755: gemini-mcp-tool OS Command Injection and File Exfiltration via Prompt Quoting
- CVE-2026-33634 Aquasecurity Trivy Embedded Malicious Code (CVE-2026-33634)
- CVE-2026-45262 FacturaScripts REST API Authenticated SQL Injection via Where::sqlColumn Parenthesis Bypass (CVE-2026-45262)
- CVE-2026-47393 PraisonAI Flask API Server Deployed Without Authentication (CVE-2026-47393)
- CVE-2026-49257 CVE-2026-49257: mcp-pinot Unauthenticated Tool Invocation via Default oauth_enabled=False
- T1011 Exfiltration Over Other Network Medium
- T1011.001 Exfiltration Over Bluetooth
- T1020 Automated Exfiltration
- T1020.001 Traffic Duplication
- T1029 Scheduled Transfer
- T1030 Data Transfer Size Limits
- T1041 Exfiltration Over C2 Channel
- T1048 Exfiltration Over Alternative Protocol
- T1048.001 Exfiltration Over Symmetric Encrypted Non-C2 Protocol
- T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
- T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol
- T1052 Exfiltration Over Physical Medium
- T1052.001 Exfiltration over USB
- T1537 Transfer Data to Cloud Account
- T1567 Exfiltration Over Web Service
- T1567.001 Exfiltration to Code Repository
- T1567.002 Exfiltration to Cloud Storage
- T1567.003 Exfiltration to Text Storage Sites
- T1567.004 Exfiltration Over Webhook
- THREAT-ArchiveStaging-ScheduledExfil Scheduled Batch Exfiltration of Compressed Archive Staging
- THREAT-Bluetooth-AirGapCourierExfil Air-Gap Bridging via Rogue Bluetooth Re-Enablement and Courier Device Pairing
- THREAT-CloudCLI-ScheduledExfil Scheduled Transfer via Cloud Sync/Backup CLI Tools
- THREAT-CloudControlPlane-CrossAccountExfil Cloud-Native Data Exfiltration via Cross-Account Resource Sharing
- THREAT-CloudStorage-DataExfil Data Exfiltration via Cloud Storage Services
- THREAT-CodeRepo-GistExfil Data Exfiltration via GitHub Gists and Private Code Repositories
- THREAT-DiscordWebhook-InfostealerExfil Infostealer Credential Exfiltration via Discord Webhook
- THREAT-DNSTunnel-Exfil DNS Tunneling for Covert Data Exfiltration
- THREAT-DNSTunneling-Exfiltration Data Exfiltration via DNS Tunneling Tools
- THREAT-Exfil-ScheduledBulkTransfer Scheduled Off-Hours Bulk Data Transfer
- THREAT-Exfil-USBRemovableMedia Data Exfiltration via USB Removable Media
- THREAT-Exfiltration-ICMPTunnel Data Exfiltration via ICMP Tunneling
- THREAT-Exfiltration-LinuxCronScheduledExfil Scheduled Data Exfiltration via Linux Cron Jobs
- THREAT-Exfiltration-M365AnonymousShareLinks Data Exfiltration via Anonymous SharePoint/OneDrive Sharing Links
- THREAT-ICMP-C2Exfiltration Data Exfiltration via ICMP Covert Channel
- THREAT-NetworkTap-RogueSPANExfil Unauthorized On-Premises SPAN/RSPAN/ERSPAN Configuration for Passive Traffic Exfiltration
- THREAT-PasteSite-ChunkedDeadDropExfil Chunked Multi-Paste Exfiltration to Text Storage Dead Drops
- THREAT-PasteSite-TextStorageExfil Data Exfiltration to Public Paste and Text-Storage Sites
- THREAT-Ransomware-AffiliateExfilTooling Ransomware-Affiliate Custom Exfiltration Tooling (StealBit & Exmatter)
- THREAT-Rclone-AutomatedCloudSync Automated Bulk Data Exfiltration via rclone Cloud-Sync Tooling
- THREAT-SFTPTunnel-EncryptedProtocolExfil Data Exfiltration Over Encrypted Non-C2 Protocol (SFTP/FTPS/rsync-over-SSH)
- THREAT-SMTP-Exfiltration Data Exfiltration via Outbound SMTP
- THREAT-USB-AirGapBridging Air-Gap Bridging Exfiltration via Shared USB Media
- THREAT-USBTethering-NetworkBypassExfil Data Exfiltration via USB Cellular Modem / Mobile Hotspot Tethering (Corporate Network Bypass)
- THREAT-WebhookAbuse-Exfiltration Data Exfiltration via Abused Chat/Collaboration Webhooks
Related tactics
266 detections
225 detections