If you are not sure if the website you would like to visit is secure, you can verify it here. Enter the website address of the page and see parts of its content and the thumbnail images on this site. None (if any) dangerous scripts on the referenced page will be executed. Additionally, if the selected site contains subpages, you can verify it (review) in batches containing 5 pages.
favicon.ico: attack.mitre.org/tactics/TA0010 - Exfiltration, Tactic TA0010 - .

site address: attack.mitre.org/tactics/TA0010 redirected to: attack.mitre.org/tactics/TA0010

site title: Exfiltration, Tactic TA0010 - Enterprise MITRE ATT&CK®

Our opinion (on Tuesday 18 August 2026 11:18:22 UTC):

GREEN status (no comments) - no comments
After content analysis of this website we propose the following hashtags:


page from cache: 5 hours ago
Meta tags:

Headings (most frequently used words):

techniques, exfiltration,

Text of the page (most frequently used words):
the (43), data (40), may (31), and (30), over (28), #exfiltration (27), control (21), adversaries (20), command (20), network (20), channel (18), exfiltrate (13), for (11), att (10), all (10), than (10), such (9), storage (9), protocol (9), other (8), are (7), enterprise (7), techniques (7), cloud (7), server (7), services (7), that (7), device (7), steal (7), could (6), traffic (6), their (6), used (6), from (6), existing (6), also (6), medium (6), use (5), ics (5), mobile (5), none (5), certain (5), webhook (5), rather (5), primary (5), 001 (5), usb (5), physical (5), exfiltrating (5), encrypted (5), alternate (5), location (5), mitre (4), service (4), transfer (4), code (4), often (4), via (4), adversary (4), attempt (4), bluetooth (4), connection (4), sent (4), main (4), cti (3), detection (3), defenses (3), tactics (3), this (3), with (3), can (3), repository (3), these (3), text (3), sites (3), internet (3), web (3), compromise (3), occur (3), drive (3), non (3), size (3), version (3), include (3), 2026 (2), corporation (2), domains (2), resources (2), reference (2), campaigns (2), software (2), groups (2), components (2), analytics (2), strategies (2), assets (2), mitigations (2), matrices (2), core (2), objects (2), transferring (2), through (2), another (2), account (2), they (2), same (2), normal (2), endpoint (2), client (2), github (2), instead (2), com (2), 003 (2), 002 (2), api (2), https (2), external (2), already (2), circumstances (2), air (2), gapped (2), introduced (2), user (2), final (2), point (2), hop (2), between (2), otherwise (2), disconnected (2), systems (2), removable (2), cellular (2), processing (2), wired (2), using (2), different (2), example (2), communications (2), avoid (2), limits (2), mirroring (2), devices (2), analysis (2), more (2), automated (2), october (2), ta0010 (2), ckcon (2), person (2), tickets (2), faq (2), 2015, registered, trademarks, cookie, preferences, website, changelog, privacy, policy, terms, contact, reset, filters, sub, including, sharing, syncing, creating, backups, environments, t1537, schedule, performed, only, times, day, intervals, done, blend, patterns, activity, availability, scheduled, t1029, webhooks, simple, mechanisms, allowing, push, http, without, need, continuously, poll, many, public, commercial, discord, slack, support, creation, endpoints, jira, trello, when, changes, happen, linked, pushing, update, modifying, ticket, will, automatically, post, consuming, application, site, 004, commonly, developers, share, information, pastebin, allow, edit, retrieval, remote, repositories, accessible, access, apis, which, gives, additional, level, protection, legitimate, popular, acting, mechanism, give, significant, amount, cover, due, likelihood, hosts, within, communicating, them, prior, firewall, rules, exist, permit, t1567, connected, media, hard, phone, mp3, player, t1052, opt, communication, wifi, modem, radio, frequency, t1011, stolen, encoded, into, t1041, unencrypted, asymmetrically, asymmetric, symmetrically, symmetric, alternative, t1048, fixed, chunks, whole, files, limit, packet, sizes, below, thresholds, approach, triggering, threshold, alerts, t1030, leverage, order, automate, compromised, infrastructure, native, feature, some, configured, forward, one, destinations, analyzer, monitoring, duplication, sensitive, documents, after, being, gathered, during, collection, t1020, description, name, live, permalink, april, 2025, last, modified, 2018, created, consists, your, once, collected, package, while, removing, compression, encryption, getting, out, target, typically, putting, transmission, trying, home, open, join, mclean, hotel, details, found, register, here, search, blog, contribute, benefactors, legal, branding, updates, history, engage, tools, advisory, council, learn, about, get, started, detections, tactic,


Text of the page (random words):
exfiltration tactic ta0010 enterprise mitre att ck matrices enterprise mobile ics tactics enterprise mobile ics techniques enterprise mobile ics defenses mitigations enterprise mobile ics assets detections detection strategies analytics data components cti groups software campaigns resources get started learn more about att ck att ck advisory council att ckcon att ck data tools faq engage with att ck version history updates legal branding benefactors contribute blog search att ckcon 7 0 in person tickets are open join us october 27 28 2026 in mclean va register here for in person tickets hotel and location details can be found in the faq home tactics enterprise exfiltration exfiltration the adversary is trying to steal data exfiltration consists of techniques that adversaries may use to steal data from your network once they ve collected data adversaries often package it to avoid detection while removing it this can include compression and encryption techniques for getting data out of a target network typically include transferring it over their command and control channel or an alternate channel and may also include putting size limits on the transmission id ta0010 created 17 october 2018 last modified 25 april 2025 version permalink live version techniques techniques 9 id name description t1020 automated exfiltration adversaries may exfiltrate data such as sensitive documents through the use of automated processing after being gathered during collection 001 traffic duplication adversaries may leverage traffic mirroring in order to automate data exfiltration over compromised infrastructure traffic mirroring is a native feature for some devices often used for network analysis for example devices may be configured to forward network traffic to one or more destinations for analysis by a network analyzer or other monitoring device t1030 data transfer size limits an adversary may exfiltrate data in fixed size chunks instead of whole files or limit packet sizes below certain thresholds this approach may be used to avoid triggering network data transfer threshold alerts t1048 exfiltration over alternative protocol adversaries may steal data by exfiltrating it over a different protocol than that of the existing command and control channel the data may also be sent to an alternate network location from the main command and control server 001 exfiltration over symmetric encrypted non c2 protocol adversaries may steal data by exfiltrating it over a symmetrically encrypted network protocol other than that of the existing command and control channel the data may also be sent to an alternate network location from the main command and control server 002 exfiltration over asymmetric encrypted non c2 protocol adversaries may steal data by exfiltrating it over an asymmetrically encrypted network protocol other than that of the existing command and control channel the data may also be sent to an alternate network location from the main command and control server 003 exfiltration over unencrypted non c2 protocol adversaries may steal data by exfiltrating it over an un encrypted network protocol other than that of the existing command and control channel the data may also be sent to an alternate network location from the main command and control server t1041 exfiltration over c2 channel adversaries may steal data by exfiltrating it over an existing command and control channel stolen data is encoded into the normal communications channel using the same protocol as command and control communications t1011 exfiltration over other network medium adversaries may attempt to exfiltrate data over a different network medium than the command and control channel if the command and control network is a wired internet connection the exfiltration may occur for example over a wifi connection modem cellular data connection bluetooth or another radio frequency rf channel 001 exfiltration over bluetooth adversaries may attempt to exfiltrate data over bluetooth rather than the command and control channel if the command and control network is a wired internet connection an adversary may opt to exfiltrate data using a bluetooth communication channel t1052 exfiltration over physical medium adversaries may attempt to exfiltrate data via a physical medium such as a removable drive in certain circumstances such as an air gapped network compromise exfiltration could occur via a physical medium or device introduced by a user such media could be an external hard drive usb drive cellular phone mp3 player or other removable storage and processing device the physical medium or device could be used as the final exfiltration point or to hop between otherwise disconnected systems 001 exfiltration over usb adversaries may attempt to exfiltrate data over a usb connected physical device in certain circumstances such as an air gapped network compromise exfiltration could occur via a usb device introduced by a user the usb device could be used as the final exfiltration point or to hop between otherwise disconnected systems t1567 exfiltration over web service adversaries may use an existing legitimate external web service to exfiltrate data rather than their primary command and control channel popular web services acting as an exfiltration mechanism may give a significant amount of cover due to the likelihood that hosts within a network are already communicating with them prior to compromise firewall rules may also already exist to permit traffic to these services 001 exfiltration to code repository adversaries may exfiltrate data to a code repository rather than over their primary command and control channel code repositories are often accessible via an api ex https api github com access to these apis are often over https which gives the adversary an additional level of protection 002 exfiltration to cloud storage adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel cloud storage services allow for the storage edit and retrieval of data from a remote cloud storage server over the internet 003 exfiltration to text storage sites adversaries may exfiltrate data to text storage sites instead of their primary command and control channel text storage sites such as pastebin com are commonly used by developers to share code and other information 004 exfiltration over webhook adversaries may exfiltrate data to a webhook endpoint rather than over their primary command and control channel webhooks are simple mechanisms for allowing a server to push data over http s to a client without the need for the client to continuously poll the server many public and commercial services such as discord slack and webhook site support the creation of webhook endpoints that can be used by other services such as github jira or trello when changes happen in the linked services such as pushing a repository update or modifying a ticket these services will automatically post the data to the webhook endpoint for use by the consuming application t1029 scheduled transfer adversaries may schedule data exfiltration to be performed only at certain times of day or at certain intervals this could be done to blend traffic patterns with normal activity or availability t1537 transfer data to cloud account adversaries may exfiltrate data by transferring the data including through sharing syncing and creating backups of cloud environments to another cloud account they control on the same service core objects all core att ck objects all none matrices tactics techniques sub techniques defenses all defenses all none mitigations assets detection strategies analytics data components cti all cti all none groups software campaigns reference all reference all none resources domains all domains all none enterprise mobile ics reset filters contact us terms of use privacy policy website changelog cookie preferences 2015 2026 the mitre corporation mitre att ck and att ck are registered trademarks of the mitre corporation
Images from subpage: "attack.mitre.org/tactics/enterprise/" Verify
Images from subpage: "attack.mitre.org/tactics/mobile/" Verify
Images from subpage: "attack.mitre.org/tactics/ics/" Verify
Images from subpage: "attack.mitre.org/techniques/" Verify
Images from subpage: "attack.mitre.org/techniques/enterprise/" Verify

Verified site has: 61 subpage(s). Do you want to verify them? Verify pages:

1-5 6-10 11-15 16-20 21-25 26-30 31-35 36-40 41-45 46-50
51-55 56-60 61-61


The site also has references to the 1 subdomain(s)

  mitre.org  Verify


Top 50 hastags from of all verified websites.

Supplementary Information (add-on for SEO geeks)*- See more on header.verify-www.com

Header

HTTP/2 301
server GitHub.com
content-type text/html
x-origin-cache HIT
location htt????/attack.mitre.org/tactics/TA0010/
access-control-allow-origin *
expires Tue, 18 Aug 2026 05:39:41 GMT
cache-control max-age=600
x-proxy-cache MISS
x-github-request-id 3B1E:09C0:1FFF57:218F7D:6A83EDC5
x-github-edge-region uksouth
accept-ranges bytes
age 0
date Tue, 18 Aug 2026 05:29:41 GMT
via 1.1 varnish
x-served-by cache-lcy-egml8630023-LCY
x-cache MISS
x-cache-hits 0
x-timer S1787030982.907294,VS0,VE88
vary Accept-Encoding
x-fastly-request-id a7a0b8b85d71c7fbd272d8db7f3c51cec0696fec
content-length 162
HTTP/2 200
server GitHub.com
content-type text/html; charset=utf-8
x-origin-cache HIT
last-modified Fri, 07 Aug 2026 14:24:07 GMT
access-control-allow-origin *
etag W/ 6a75ea87-ac41
expires Tue, 18 Aug 2026 05:39:42 GMT
cache-control max-age=600
content-encoding gzip
x-proxy-cache MISS
x-github-request-id B716:33A9F7:27CBF4:29B107:6A83EDC5
x-github-edge-region uksouth
accept-ranges bytes
age 0
date Tue, 18 Aug 2026 05:29:42 GMT
via 1.1 varnish
x-served-by cache-lcy-egml8630023-LCY
x-cache MISS
x-cache-hits 0
x-timer S1787030982.003086,VS0,VE83
vary Accept-Encoding
x-fastly-request-id b3bb2a719a9a1cc298190831ee8b6e6afe41282e
content-length 7371

Meta Tags

title="Exfiltration, Tactic TA0010 - Enterprise | MITRE ATT&CK®"
name="google-site-verification" content="2oJKLqNN62z6AOCb0A0IXGtbQuj-lev5YPAHFF_cbHQ"
charset="utf-8"
name="viewport" content="width=device-width, initial-scale=1,shrink-to-fit=no"
http-equiv="X-UA-Compatible" content="IE=edge"

Load Info

page size44097
load time (s)0.670642
redirect count1
speed download11001
server IP 185.199.108.153
* all occurrences of the string "http://" have been changed to "htt???/"