If you are not sure if the website you would like to visit is secure, you can verify it here. Enter the website address of the page and see parts of its content and the thumbnail images on this site. None (if any) dangerous scripts on the referenced page will be executed. Additionally, if the selected site contains subpages, you can verify it (review) in batches containing 5 pages.
favicon.ico: attack.mitre.org/techniques/T1537 - Transfer Data to Cloud Account.

site address: attack.mitre.org/techniques/T1537 redirected to: attack.mitre.org/techniques/T1537

site title: Transfer Data to Cloud Account, Technique T1537 - Enterprise MITRE ATT&CK®

Our opinion (on Sunday 16 August 2026 20:04:50 UTC):

GREEN status (no comments) - no comments
After content analysis of this website we propose the following hashtags:



Meta tags:

Headings (most frequently used words):

transfer, data, to, cloud, account, procedure, examples, mitigations, detection, strategy, references,

Text of the page (most frequently used words):
data (25), cloud (19), the (16), 2024 (12), and (11), retrieved (11), att (10), all (10), sharing (10), techniques (8), for (8), #account (8), enterprise (7), transfers (7), microsoft (6), march (6), external (6), transfer (6), ics (5), mobile (5), none (5), august (5), mitre (4), use (4), domains (4), detection (4), october (4), loss (4), redcurl (4), access (4), with (4), file (4), provider (4), exfiltrate (4), version (4), may (4), resources (3), software (3), cti (3), mitigations (3), defenses (3), sub (3), google (3), about (3), prevention (3), 2025 (3), storm (3), 0501 (3), inc (3), azure (3), storage (3), shared (3), sas (3), detects (3), through (3), generation (3), user (3), from (3), accounts (3), same (3), description (3), can (3), network (3), has (3), used (3), adversaries (3), 2026 (2), corporation (2), are (2), policy (2), reference (2), campaigns (2), groups (2), components (2), analytics (2), strategies (2), assets (2), tactics (2), matrices (2), core (2), objects (2), 2023 (2), manage (2), sharepoint (2), onedrive (2), organization (2), prevent (2), january (2), learn (2), threat (2), based (2), ransomware (2), group (2), 2021 (2), november (2), june (2), using (2), aws (2), environments (2), saas (2), mechanisms (2), share (2), tenants (2), untrusted (2), users (2), link (2), snapshot (2), victim (2), within (2), updates (2), uri (2), analytic (2), name (2), restrictions (2), certain (2), traffic (2), outside (2), environment (2), service (2), ransom (2), created (2), t1537 (2), have (2), backups (2), such (2), creating (2), normal (2), over (2), control (2), another (2), ckcon (2), person (2), tickets (2), faq (2), 2015, registered, trademarks, cookie, preferences, website, changelog, privacy, terms, contact, reset, filters, settings, 365, your, workspace, dlp, intelligence, evolving, lead, awakening, 2020, pentest, you, didn, know, counter, unit, research, team, april, gold, ionic, deploys, mueller, 2018, july, indictment, united, states, america, viktor, borisovich, netyksho, grant, limited, signatures, clint, gibler, scott, piper, lesser, known, attacking, references, built, ownership, critical, api, calls, features, an1582, activity, that, shares, syncs, files, via, actions, involving, non, whitelisted, partner, an1581, backup, exports, object, owned, other, identities, bucket, an1580, cross, platform, det0573, strategy, limit, iam, policies, least, privileges, required, management, m1018, configure, appropriate, services, example, drive, turned, off, altogether, blocked, restricted, configuration, m1054, implement, filtering, prohibit, vpcs, filter, m1037, block, sensitive, being, individuals, m1057, mitigation, copied, victims, their, own, infrastructure, leveraging, azcopy, cli, g1053, particular, megatools, utilities, were, mega, g1039, megasync, g1032, procedure, examples, live, permalink, last, modified, 2019, darin, smith, cisco, extrahop, gabriel, currie, praetorian, contributors, iaas, office, suite, platforms, exfiltration, tactic, incidents, been, observed, where, instances, transferred, them, separate, also, native, adversary, controlled, anonymous, links, signature, defender, who, monitoring, large, command, channels, not, watching, utilize, existing, apis, internal, address, space, blend, into, avoid, interfaces, transferring, including, syncing, they, home, open, join, mclean, hotel, location, details, found, register, here, search, blog, contribute, benefactors, legal, branding, history, engage, tools, advisory, council, more, get, started, detections, technique,


Text of the page (random words):
transfer data to cloud account technique t1537 enterprise mitre att ck matrices enterprise mobile ics tactics enterprise mobile ics techniques enterprise mobile ics defenses mitigations enterprise mobile ics assets detections detection strategies analytics data components cti groups software campaigns resources get started learn more about att ck att ck advisory council att ckcon att ck data tools faq engage with att ck version history updates legal branding benefactors contribute blog search att ckcon 7 0 in person tickets are open join us october 27 28 2026 in mclean va register here for in person tickets hotel and location details can be found in the faq home techniques enterprise transfer data to cloud account transfer data to cloud account adversaries may exfiltrate data by transferring the data including through sharing syncing and creating backups of cloud environments to another cloud account they control on the same service a defender who is monitoring for large transfers to outside the cloud environment through normal file transfers or over command and control channels may not be watching for data transfers to another account within the same cloud provider such transfers may utilize existing cloud provider apis and the internal address space of the cloud provider to blend into normal traffic or avoid data transfers over external network interfaces 1 adversaries may also use cloud native mechanisms to share victim data with adversary controlled cloud accounts such as creating anonymous file sharing links or in azure a shared access signature sas uri 2 incidents have been observed where adversaries have created backups of cloud instances and transferred them to separate accounts 3 id t1537 sub techniques no sub techniques ⓘ tactic exfiltration ⓘ platforms iaas office suite saas contributors darin smith cisco extrahop gabriel currie praetorian version 1 5 created 30 august 2019 last modified 24 october 2025 version permalink live version procedure examples id name description g1032 inc ransom inc ransom has used megasync to exfiltrate data to the cloud 4 g1039 redcurl redcurl has used cloud storage to exfiltrate data in particular the megatools utilities were used to exfiltrate data to mega a file storage service 5 6 g1053 storm 0501 storm 0501 has copied data from the victims environment to their own infrastructure leveraging azcopy cli 7 mitigations id mitigation description m1057 data loss prevention data loss prevention can prevent and block sensitive data from being shared with individuals outside an organization 8 9 m1037 filter network traffic implement network based filtering restrictions to prohibit data transfers to untrusted vpcs m1054 software configuration configure appropriate data sharing restrictions in cloud services for example external sharing in microsoft sharepoint and google drive can be turned off altogether blocked for certain domains or restricted to certain users 10 11 m1018 user account management limit user account and iam policies to the least privileges required detection strategy id name analytic id analytic description det0573 cross platform detection of data transfer to cloud account an1580 detects snapshot sharing backup exports or data object transfers from victim owned cloud accounts to other cloud identities within the same provider e g aws azure using snapshot sharing s3 bucket policy updates or sas uri generation an1581 detects user activity that shares or syncs files with external domains via link generation onedrive external sharing or file transfer actions involving non whitelisted partner tenants an1582 detects use of built in saas sharing mechanisms to transfer ownership or share access of critical data to external tenants or untrusted users through api calls or link generation features references clint gibler and scott piper 2021 january 4 lesser known techniques for attacking aws environments retrieved march 4 2024 microsoft 2023 june 7 grant limited access to azure storage resources using shared access signatures sas retrieved march 4 2024 mueller r 2018 july 13 indictment united states of america vs viktor borisovich netyksho et al retrieved november 17 2024 counter threat unit research team 2024 april 15 gold ionic deploys inc ransomware retrieved june 5 2024 group ib 2020 august redcurl the pentest you didn t know about retrieved august 9 2024 group ib 2021 november redcurl the awakening retrieved august 14 2024 microsoft threat intelligence 2025 august 27 storm 0501 s evolving techniques lead to cloud based ransomware retrieved october 19 2025 microsoft 2024 january 9 learn about data loss prevention retrieved march 4 2024 google n d use workspace dlp to prevent data loss retrieved march 4 2024 google n d manage external sharing for your organization retrieved march 4 2024 microsoft 2023 october 11 manage sharing settings for sharepoint and onedrive in microsoft 365 retrieved march 4 2024 core objects all core att ck objects all none matrices tactics techniques sub techniques defenses all defenses all none mitigations assets detection strategies analytics data components cti all cti all none groups software campaigns reference all reference all none resources domains all domains all none enterprise mobile ics reset filters contact us terms of use privacy policy website changelog cookie preferences 2015 2026 the mitre corporation mitre att ck and att ck are registered trademarks of the mitre corporation
Images from subpage: "attack.mitre.org/resources/engage-with-attack/contact/... " Verify
Images from subpage: "attack.mitre.org/resources/versions/" Verify
Images from subpage: "attack.mitre.org/resources/updates/" Verify
Images from subpage: "attack.mitre.org/resources/legal-and-branding/" Verify
Images from subpage: "attack.mitre.org/resources/engage-with-attack/benefactors/... " Verify

Verified site has: 51 subpage(s). Do you want to verify them? Verify pages:

1-5 6-10 11-15 16-20 21-25 26-30 31-35 36-40 41-45 46-50
51-51


The site also has references to the 1 subdomain(s)

  mitre.org  Verify


Top 50 hastags from of all verified websites.

Supplementary Information (add-on for SEO geeks)*- See more on header.verify-www.com

Header

HTTP/2 301
server GitHub.com
content-type text/html
x-origin-cache HIT
location htt????/attack.mitre.org/techniques/T1537/
access-control-allow-origin *
expires Sun, 16 Aug 2026 20:14:50 GMT
cache-control max-age=600
x-proxy-cache MISS
x-github-request-id 6F56:175124:7B27A5D:7BD7585:6A8217E2
x-github-edge-region fra
accept-ranges bytes
age 0
date Sun, 16 Aug 2026 20:04:50 GMT
via 1.1 varnish
x-served-by cache-rtm-ehrd2290048-RTM
x-cache MISS
x-cache-hits 0
x-timer S1786910690.413076,VS0,VE106
vary Accept-Encoding
x-fastly-request-id f831bb79bb1f6f8102cc0b0f4b1ce29c41b6c55f
content-length 162
HTTP/2 200
server GitHub.com
content-type text/html; charset=utf-8
x-origin-cache HIT
last-modified Fri, 07 Aug 2026 14:24:21 GMT
access-control-allow-origin *
etag W/ 6a75ea95-c43a
expires Sun, 16 Aug 2026 20:14:50 GMT
cache-control max-age=600
content-encoding gzip
x-proxy-cache MISS
x-github-request-id AE02:190D74:76C05D9:776FBCD:6A8217E2
x-github-edge-region fra
accept-ranges bytes
date Sun, 16 Aug 2026 20:04:50 GMT
via 1.1 varnish
age 0
x-served-by cache-rtm-ehrd2290048-RTM
x-cache MISS
x-cache-hits 0
x-timer S1786910691.529512,VS0,VE110
vary Accept-Encoding
x-fastly-request-id b7989f3b02dbdb94b6a5b2cf721c9faac292bb94
content-length 8486

Meta Tags

title="Transfer Data to Cloud Account, Technique T1537 - Enterprise | MITRE ATT&CK®"
name="google-site-verification" content="2oJKLqNN62z6AOCb0A0IXGtbQuj-lev5YPAHFF_cbHQ"
charset="utf-8"
name="viewport" content="width=device-width, initial-scale=1,shrink-to-fit=no"
http-equiv="X-UA-Compatible" content="IE=edge"

Load Info

page size8486
load time (s)0.729389
redirect count1
speed download11640
server IP 185.199.109.153
* all occurrences of the string "http://" have been changed to "htt???/"