TA0010

Exfiltration Detection Rules

The adversary is trying to steal data. Exfiltration consists of techniques that adversaries may use to steal data from your network. Once they’ve collected data, adversaries often package it to avoid detection while removing it. This can include compression and encryption. Techniques for getting data out of a target network typically include transferring it over their command and control channel or an alternate channel and may also include putting size limits on the transmission.

df00tech ships 50 production-ready detection rules mapped to the Exfiltration tactic (TA0010). Each rule below includes copy-paste queries for Microsoft Sentinel (KQL), Splunk (SPL), Elastic (EQL), QRadar, Sumo Logic, Chronicle and LogScale, with data-source requirements, severity and false-positive guidance — free to use.

Unlock the full Pro package

Response playbooks, investigation guides and atomic tests for every technique — from £29/mo.

Upgrade to Pro

Exfiltration detections (50)

Related tactics

All MITRE ATT&CK Tactics