If you are not sure if the website you would like to visit is secure, you can verify it here. Enter the website address of the page and see parts of its content and the thumbnail images on this site. None (if any) dangerous scripts on the referenced page will be executed. Additionally, if the selected site contains subpages, you can verify it (review) in batches containing 5 pages.
favicon.ico: attack.mitre.org/techniques/T1020 - Automated Exfiltration, Techni.

site address: attack.mitre.org/techniques/T1020 redirected to: attack.mitre.org/techniques/T1020

site title: Automated Exfiltration, Technique T1020 - Enterprise MITRE ATT&CK®

Our opinion (on Saturday 29 August 2026 0:59:33 UTC):

GREEN status (no comments) - no comments
After content analysis of this website we propose the following hashtags:



Meta tags:

Headings (most frequently used words):

automated, exfiltration, procedure, examples, mitigations, detection, strategy, references, sub, techniques,

Text of the page (most frequently used words):
the (38), retrieved (36), and (29), data (22), automatically (20), 2020 (15), files (15), exfiltration (14), 2024 (13), may (12), collected (12), has (12), june (11), att (10), all (10), for (10), #automated (10), exfiltrate (10), july (9), stealer (9), 2019 (8), 2022 (8), server (8), enterprise (7), techniques (7), 2016 (7), august (7), from (7), via (7), can (7), 2026 (6), november (6), group (6), apt (6), march (6), 2021 (6), servers (6), used (6), ics (5), mobile (5), none (5), detection (5), february (5), back (5), with (5), december (5), information (5), cyber (5), 2025 (5), raccoon (5), version (5), threat (5), that (5), mitre (4), are (4), 2014 (4), air (4), gapped (4), january (4), attack (4), september (4), new (4), october (4), tools (4), credentials (4), rover (4), redcurl (4), remote (4), control (4), actors (4), using (4), sends (4), t1020 (4), use (3), groups (3), cti (3), mitigations (3), defenses (3), sub (3), cert (3), winter (3), vivern (3), tropic (3), trooper (3), targets (3), campaign (3), compromised (3), about (3), april (3), tajmahal (3), strongpity (3), strelastealer (3), sidewinder (3), adversary (3), salesforce (3), outsteel (3), machete (3), government (3), lightneuron (3), kimsuky (3), open (3), frankenstein (3), ebury (3), doki (3), cloud (3), crutch (3), cosmicduke (3), based (3), attor (3), gamaredon (3), its (3), scripts (3), name (3), script (3), victim (3), file (3), exfiltrates (3), when (3), after (3), ability (3), sent (3), documents (3), gathered (3), command (3), network (3), during (3), upload (3), exfiltrated (3), empire (3), over (3), corporation (2), domains (2), resources (2), reference (2), campaigns (2), software (2), components (2), analytics (2), strategies (2), assets (2), tactics (2), matrices (2), core (2), objects (2), 2023 (2), target (2), calvet (2), espionage (2), networks (2), 2017 (2), analysis (2), you (2), know (2), global (2), blog (2), hromcova (2), stealing (2), malware (2), pierre (2), bourhis (2), quentin (2), bourgue (2), sekoia (2), tdr (2), part (2), operation (2), organizations (2), document (2), under (2), faou (2), turla (2), one (2), email (2), alive (2), into (2), léveillé (2), large (2), linux (2), commands (2), also (2), external (2), transfer (2), background (2), transmitting (2), scheduled (2), strategy (2), analytic (2), description (2), technique (2), system (2), identified (2), http (2), machine (2), being (2), usbstealer (2), sensitive (2), systems (2), found (2), extensions (2), configuration (2), uploads (2), tinytyphon (2), post (2), stolen (2), teampcp (2), collection (2), solar (2), configured (2), send (2), controlled (2), shimratreporter (2), list (2), them (2), every (2), minutes (2), peppy (2), ke3chang (2), hannotog (2), arcanedoor (2), 001 (2), such (2), ckcon (2), person (2), tickets (2), faq (2), 2015, registered, trademarks, cookie, preferences, website, changelog, privacy, policy, terms, contact, reset, filters, uac, 0114, aka, ukrainian, polish, gov, entities, 5909, sednit, attacking, chen, usbferry, environments, settle, monsoon, mccarthy, trivy, everything, need, latest, supply, chain, great, project, sophisticated, framework, tudorica, revealing, trojanized, working, hours, infrastructure, mercer, promethium, extends, reach, strongpity3, golo, mühr, joe, fasulo, charlotte, hammond, ibm, force, strela, today, invoice, tomorrow, phish, dcso, cytec, shortandmalicious, aims, mail, burgher, oilrig, outer, space, juicy, mix, same, rig, drill, pipes, hegel, perspective, yonathan, klijnsma, mofang, politically, motivated, fbi, division, criminal, unc6040, unc6395, compromising, instances, theft, extortion, ray, hayashi, indian, ambassador, afghanistan, awakening, pentest, didn, depth, return, dead, s2w, talon, huss, transparent, tribe, unit, spear, phishing, attacks, ukraine, payloads, include, downloader, saintbot, eset, just, got, sharper, venezuelan, institutions, away, code, execution, varadharajan, krishnasamy, aditya, sood, reconnaissance, operational, blueprint, mstic, nickel, targeting, across, latin, america, europe, symntec, hunter, team, billbug, state, sponsored, actor, authority, agencies, multiple, asian, countries, adamitis, cobble, together, source, pieces, monstrous, marc, etienne, but, unseen, bilodeau, bureau, dorais, joncas, vanheuverzwijn, windigo, vivisection, side, credential, fishbein, kajiloti, watch, your, containers, infecting, docker, keeping, door, secure, labs, cosmu, twist, miniduke, tor, communications, meet, fantasy, creature, spy, platform, canadian, centre, security, activity, impacting, cisco, asa, vpns, boutin, grows, game, references, observation, launchagents, launchdaemons, establishing, periodic, connections, indicative, an1115, cron, daemons, repeatedly, ips, urls, an1114, periodically, destinations, tasks, processes, an1113, det0397, this, type, cannot, easily, mitigated, preventive, controls, since, abuse, features, delivered, powershell, capable, recursively, scanning, machines, looking, various, types, before, exfiltrating, g1035, removable, media, infected, device, connects, initially, connected, internet, enabled, s0136, copy, function, usb, storage, g0081, matching, s0131, compress, encrypt, scan, aquasecurtiy, org, method, fails, attempts, github_token, create, repo, there, s9041, manage, queue, egress, s0467, s0491, following, s1183, exfitrate, s1166, attacker, g0121, compiled, report, s0445, api, queries, volumes, c0059, searches, local, drives, predefined, keylogger, screenshots, regular, timeframe, s0090, batch, g1039, will, collect, received, nodes, s1148, keylogs, s0643, s1017, s0409, specified, directory, s0395, executes, successful, checks, presence, pre, designated, staged, filenames, g0094, performed, frequent, g0004, encyrpted, s1211, modules, g0047, which, was, c0001, s0363, not, two, weeks, encrypts, public, key, udp, address, located, dns, txt, record, s0377, gathers, hardcoded, addresses, ngrok, url, s0600, dropbox, s0538, ftp, s0050, uploader, plugin, log, s0438, included, scripted, c0046, procedure, examples, live, permalink, last, modified, created, extrahop, contributors, devices, windows, macos, platforms, tactic, other, likely, apply, well, out, alternative, protocol, channel, adversaries, through, processing, traffic, duplication, home, join, mclean, hotel, location, details, register, here, search, contribute, benefactors, legal, branding, updates, history, engage, advisory, council, learn, more, get, started, detections,


Text of the page (random words):
automated exfiltration technique t1020 enterprise mitre att ck matrices enterprise mobile ics tactics enterprise mobile ics techniques enterprise mobile ics defenses mitigations enterprise mobile ics assets detections detection strategies analytics data components cti groups software campaigns resources get started learn more about att ck att ck advisory council att ckcon att ck data tools faq engage with att ck version history updates legal branding benefactors contribute blog search att ckcon 7 0 in person tickets are open join us october 27 28 2026 in mclean va register here for in person tickets hotel and location details can be found in the faq home techniques enterprise automated exfiltration automated exfiltration sub techniques 1 id name t1020 001 traffic duplication adversaries may exfiltrate data such as sensitive documents through the use of automated processing after being gathered during collection 1 when automated exfiltration is used other exfiltration techniques likely apply as well to transfer the information out of the network such as exfiltration over c2 channel and exfiltration over alternative protocol id t1020 sub techniques t1020 001 ⓘ tactic exfiltration ⓘ platforms linux network devices windows macos contributors extrahop version 1 3 created 31 may 2017 last modified 12 may 2026 version permalink live version procedure examples id name description c0046 arcanedoor arcanedoor included scripted exfiltration of collected data 2 s0438 attor attor has a file uploader plugin that automatically exfiltrates the collected data and log files to the c2 server 3 s0050 cosmicduke cosmicduke exfiltrates collected files automatically over ftp to remote servers 4 s0538 crutch crutch has automatically exfiltrated stolen files to dropbox 5 s0600 doki doki has used a script that gathers information from a hardcoded list of ip addresses and uploads to an ngrok url 6 s0377 ebury if credentials are not collected for two weeks ebury encrypts the credentials using a public key and sends them via udp to an ip address located in the dns txt record 7 8 s0363 empire empire has the ability to automatically send collected data back to the threat actors c2 9 c0001 frankenstein during frankenstein the threat actors collected information via empire which was automatically sent back to the adversary s c2 9 g0047 gamaredon group gamaredon group has used modules that automatically upload gathered documents to the c2 server 1 s1211 hannotog hannotog can upload encyrpted data for exfiltration 10 g0004 ke3chang ke3chang has performed frequent and scheduled data exfiltration from compromised networks 11 g0094 kimsuky kimsuky has exfiltrated data to c2 servers using an automated script that executes every 10 minutes and after successful checks for the presence of pre designated staged filenames 12 s0395 lightneuron lightneuron can be configured to automatically exfiltrate files under a specified directory 13 s0409 machete machete s collected files are exfiltrated automatically to remote servers 14 s1017 outsteel outsteel can automatically upload collected files to its c2 server 15 s0643 peppy peppy has the ability to automatically exfiltrate files and keylogs 16 s1148 raccoon stealer raccoon stealer will automatically collect and exfiltrate data identified in received configuration files from command and control nodes 17 18 19 g1039 redcurl redcurl has used batch scripts to exfiltrate data 20 21 s0090 rover rover automatically searches for files on local drives based on a predefined list of file extensions and sends them to the command and control server every 60 minutes rover also automatically sends keylogger files and screenshots to the c2 server on a regular timeframe 22 c0059 salesforce data exfiltration during salesforce data exfiltration threat actors used api queries to automatically exfiltrate large volumes of data 23 s0445 shimratreporter shimratreporter sent collected system and network information compiled into a report to an adversary controlled c2 24 g0121 sidewinder sidewinder has configured tools to automatically send collected files to attacker controlled servers 25 s1166 solar solar can automatically exfitrate files from compromised systems 26 s1183 strelastealer strelastealer automatically sends gathered email credentials following collection to command and control servers via http post 27 28 s0491 strongpity strongpity can automatically exfiltrate collected documents to the c2 server 29 30 s0467 tajmahal tajmahal has the ability to manage an automated queue of egress files and commands sent to its c2 31 s9041 teampcp cloud stealer teampcp cloud stealer can compress and encrypt data and exfiltrate it via post to scan aquasecurtiy org if that method fails it attempts to use a stolen github_token to create a repo and exfiltrate the data there 32 s0131 tinytyphon when a document is found matching one of the extensions in the configuration tinytyphon uploads it to the c2 server 33 g0081 tropic trooper tropic trooper has used a copy function to automatically exfiltrate sensitive data from air gapped systems using usb storage 34 s0136 usbstealer usbstealer automatically exfiltrates collected files via removable media when an infected device connects to an air gapped victim machine after initially being connected to an internet enabled victim machine 35 g1035 winter vivern winter vivern delivered a powershell script capable of recursively scanning victim machines looking for various file types before exfiltrating identified files via http 36 mitigations this type of attack technique cannot be easily mitigated with preventive controls since it is based on the abuse of system features detection strategy id name analytic id analytic description det0397 automated exfiltration detection strategy an1113 detection of automated tools or scripts periodically transmitting data to external destinations using scheduled tasks or background processes an1114 background scripts e g via cron or daemons transmitting data repeatedly to remote ips or urls an1115 observation of launchagents or launchdaemons establishing periodic external connections indicative of automated data transfer references boutin j 2020 june 11 gamaredon group grows its game retrieved june 16 2020 canadian centre for cyber security 2024 april 24 cyber activity impacting cisco asa vpns retrieved january 6 2025 hromcova z 2019 october at commands tor based communications meet attor a fantasy creature and also a spy platform retrieved may 6 2020 f secure labs 2014 july cosmicduke cosmu with a twist of miniduke retrieved july 3 2014 faou m 2020 december 2 turla crutch keeping the back door open retrieved december 4 2020 fishbein n kajiloti m 2020 july 28 watch your containers doki infecting docker servers in the cloud retrieved march 30 2021 bilodeau o bureau m calvet j dorais joncas a léveillé m vanheuverzwijn b 2014 march 18 operation windigo the vivisection of a large linux server side credential stealing malware campaign retrieved february 10 2021 marc etienne m léveillé 2024 may 1 ebury is alive but unseen retrieved may 21 2024 adamitis d et al 2019 june 4 it s alive threat actors cobble together open source pieces into monstrous frankenstein campaign retrieved may 11 2020 symntec threat hunter team 2022 november 12 billbug state sponsored actor targets cert authority government agencies in multiple asian countries retrieved march 15 2025 mstic 2021 december 6 nickel targeting government organizations across latin america and europe retrieved march 18 2022 varadharajan krishnasamy aditya k sood 2025 july 29 from reconnaissance to control the operational blueprint of kimsuky apt for cyber espionage retrieved april 18 2026 faou m 2019 may turla lightneuron one email away from remote code execution retrieved june 24 2019 eset 2019 july machete just got sharper venezuelan government institutions under attack retrieved september 13 2019 unit 42 2022 february 25 spear phishing attacks target organizations in ukraine payloads include the document stealer outsteel and the downloader saintbot retrieved june 9 2022 huss d 2016 march 1 operation transparent tribe retrieved june 8 2016 s2w talon 2022 june 16 raccoon stealer is back with a new version retrieved august 1 2024 quentin bourgue pierre le bourhis sekoia tdr 2022 june 28 raccoon stealer v2 part 1 the return of the dead retrieved august 1 2024 pierre le bourhis quentin bourgue sekoia tdr 2022 june 29 raccoon stealer v2 part 2 in depth analysis retrieved august 1 2024 group ib 2020 august redcurl the pentest you didn t know about retrieved august 9 2024 group ib 2021 november redcurl the awakening retrieved august 14 2024 ray v hayashi k 2016 february 29 new malware rover targets indian ambassador to afghanistan retrieved february 29 2016 fbi cyber division 2025 september 12 cyber criminal groups unc6040 and unc6395 compromising salesforce instances for data theft and extortion retrieved october 22 2025 yonathan klijnsma 2016 may 17 mofang a politically motivated information stealing adversary retrieved may 12 2020 hegel t 2021 january 13 a global perspective of the sidewinder apt retrieved january 27 2021 hromcova z and burgher a 2023 september 21 oilrig s outer space and juicy mix same ol rig new drill pipes retrieved november 21 2024 dcso cytec blog 2022 november 8 shortandmalicious strelastealer aims for mail credentials retrieved december 31 2024 golo mühr joe fasulo charlotte hammond ibm x force 2024 november 12 strela stealer today s invoice is tomorrow s phish retrieved december 31 2024 mercer w et al 2020 june 29 promethium extends global reach with strongpity3 apt retrieved july 20 2020 tudorica r et al 2020 june 30 strongpity apt revealing trojanized tools working hours and infrastructure retrieved july 20 2020 great 2019 april 10 project tajmahal a sophisticated new apt framework retrieved october 14 2019 mccarthy r 2026 march 20 trivy compromised everything you need to know about the latest supply chain attack retrieved july 1 2026 settle a et al 2016 august 8 monsoon analysis of an apt campaign retrieved september 22 2016 chen j 2020 may 12 tropic trooper s back usbferry attack targets air gapped environments retrieved may 20 2020 calvet j 2014 november 11 sednit espionage group attacking air gapped networks retrieved january 4 2017 cert ua 2023 february 1 uac 0114 aka winter vivern to target ukrainian and polish gov entities cert ua 5909 retrieved july 29 2024 core objects all core att ck objects all none matrices tactics techniques sub techniques defenses all defenses all none mitigations assets detection strategies analytics data components cti all cti all none groups software campaigns reference all reference all none resources domains all domains all none enterprise mobile ics reset filters contact us terms of use privacy policy website changelog cookie preferences 2015 2026 the mitre corporation mitre att ck and att ck are registered trademarks of the mitre corporation
Thumbnail images (randomly selected): * Images may be subject to copyright.GREEN status (no comments)
  • External site

Verified site has: 79 subpage(s). Do you want to verify them? Verify pages:

1-5 6-10 11-15 16-20 21-25 26-30 31-35 36-40 41-45 46-50
51-55 56-60 61-65 66-70 71-75 76-79


The site also has references to the 1 subdomain(s)

  mitre.org  Verify


Top 50 hastags from of all verified websites.

Supplementary Information (add-on for SEO geeks)*- See more on header.verify-www.com

Header

HTTP/1.1 301 Moved Permanently
Connection close
Content-Length 162
Server GitHub.com
Content-Type text/html
Location htt????/attack.mitre.org/techniques/T1020
X-GitHub-Request-Id C3A0:2D6DB7:5734EF:581731:6A922EF4
x-github-edge-region fra
Accept-Ranges bytes
Age 0
Date Sat, 29 Aug 2026 00:59:33 GMT
Via 1.1 varnish
X-Served-By cache-rtm-ehrd2290026-RTM
X-Cache MISS
X-Cache-Hits 0
X-Timer S1787965173.119826,VS0,VE97
Vary Accept-Encoding
X-Fastly-Request-ID 344fd438184f46a49ef04e6426f16154ced724fc
HTTP/2 301
server GitHub.com
content-type text/html
x-origin-cache HIT
location htt????/attack.mitre.org/techniques/T1020/
access-control-allow-origin *
expires Sat, 29 Aug 2026 01:09:33 GMT
cache-control max-age=600
x-proxy-cache MISS
x-github-request-id D3C8:15BD:15217FD8:154C8B1B:6A922EF5
x-github-edge-region fra
accept-ranges bytes
age 0
date Sat, 29 Aug 2026 00:59:33 GMT
via 1.1 varnish
x-served-by cache-rtm-ehrd2290054-RTM
x-cache MISS
x-cache-hits 0
x-timer S1787965173.244429,VS0,VE107
vary Accept-Encoding
x-fastly-request-id 11b913ebe93417b9af7701e21377086845a334b8
content-length 162
HTTP/2 200
server GitHub.com
content-type text/html; charset=utf-8
x-origin-cache HIT
last-modified Fri, 07 Aug 2026 14:24:21 GMT
access-control-allow-origin *
etag W/ 6a75ea95-15ccc
expires Sat, 29 Aug 2026 01:09:33 GMT
cache-control max-age=600
content-encoding gzip
x-proxy-cache MISS
x-github-request-id D3AE:2D6DB7:57355A:58178F:6A922EF5
x-github-edge-region fra
accept-ranges bytes
date Sat, 29 Aug 2026 00:59:33 GMT
via 1.1 varnish
age 0
x-served-by cache-rtm-ehrd2290054-RTM
x-cache MISS
x-cache-hits 0
x-timer S1787965173.359949,VS0,VE116
vary Accept-Encoding
x-fastly-request-id ce7ece78187f46cc8e70e0854e16276a1bcad780
content-length 14552

Meta Tags

title="Automated Exfiltration, Technique T1020 - Enterprise | MITRE ATT&CK®"
name="google-site-verification" content="2oJKLqNN62z6AOCb0A0IXGtbQuj-lev5YPAHFF_cbHQ"
charset="utf-8"
name="viewport" content="width=device-width, initial-scale=1,shrink-to-fit=no"
http-equiv="X-UA-Compatible" content="IE=edge"

Load Info

page size14552
load time (s)0.839619
redirect count2
speed download17344
server IP 185.199.110.153
* all occurrences of the string "http://" have been changed to "htt???/"