If you are not sure if the website you would like to visit is secure, you can verify it here. Enter the website address of the page and see parts of its content and the thumbnail images on this site. None (if any) dangerous scripts on the referenced page will be executed. Additionally, if the selected site contains subpages, you can verify it (review) in batches containing 5 pages.
favicon.ico: attack.mitre.org/techniques/T1029 - Scheduled Transfer, Technique .

site address: attack.mitre.org/techniques/T1029 redirected to: attack.mitre.org/techniques/T1029

site title: Scheduled Transfer, Technique T1029 - Enterprise MITRE ATT&CK®

Our opinion (on Saturday 15 August 2026 4:56:43 UTC):

GREEN status (no comments) - no comments
After content analysis of this website we propose the following hashtags:



Meta tags:

Headings (most frequently used words):

scheduled, transfer, procedure, examples, mitigations, detection, strategy, references,

Text of the page (most frequently used words):
and (22), the (20), retrieved (19), can (13), att (10), all (10), may (10), data (9), techniques (8), 2021 (8), exfiltration (8), for (8), enterprise (7), #detection (7), scheduled (7), 2016 (6), june (6), with (6), transfer (6), based (6), network (6), time (6), ics (5), mobile (5), none (5), new (5), 2017 (5), march (5), 2018 (5), 2019 (5), from (5), used (5), specific (5), its (5), sleep (5), mitre (4), february (4), command (4), april (4), malware (4), backdoor (4), 2020 (4), signatures (4), intervals (4), set (4), every (4), hours (4), server (4), version (4), are (3), domains (3), cti (3), mitigations (3), defenses (3), sub (3), tactics (3), control (3), tinyturla (3), adversary (3), 2022 (3), shadowpad (3), threat (3), machete (3), linfo (3), faou (3), lightneuron (3), remote (3), kazuar (3), tools (3), higaisa (3), flagpro (3), agent (3), comrat (3), cobalt (3), strike (3), october (3), recurring (3), script (3), description (3), traffic (3), likely (3), over (3), has (3), only (3), minutes (3), which (3), configured (3), certain (3), normal (3), 2026 (2), corporation (2), use (2), contact (2), resources (2), reference (2), campaigns (2), software (2), groups (2), components (2), analytics (2), strategies (2), assets (2), matrices (2), core (2), objects (2), september (2), turla (2), victim (2), december (2), information (2), cyber (2), august (2), iranian (2), espionage (2), campaign (2), group (2), updates (2), eset (2), july (2), year (2), windows (2), november (2), consistent (2), external (2), timing (2), user (2), strategy (2), patterns (2), analytic (2), name (2), intrusion (2), prevention (2), infrastructure (2), activity (2), protocols (2), technique (2), tool (2), will (2), adversaries (2), change (2), such (2), when (2), shimrat (2), communications (2), specified (2), shark (2), sent (2), back (2), powerstats (2), ninja (2), during (2), working (2), jrat (2), interval (2), dipsind (2), out (2), chrommme (2), advstoreshell (2), t1029 (2), ckcon (2), person (2), tickets (2), faq (2), 2015, registered, trademarks, cookie, preferences, website, changelog, privacy, policy, terms, reset, filters, gardiner, cova, nagaraja, 2014, understanding, denying, detecting, cisco, talos, deploys, keep, secret, machines, yonathan, klijnsma, mofang, politically, motivated, stealing, clearsky, security, siamesekitten, lyceum, great, corporate, networks, singh, procedures, spear, phishing, dedola, apt, toddycat, january, 2024, just, got, sharper, venezuelan, government, institutions, under, attack, zhou, 2012, one, email, away, code, execution, levene, multiplatform, api, access, kamluk, gostev, adwind, cross, platform, rat, esc, intelligence, covid, greetings, investigation, into, methods, hada, blacktech, defender, advanced, hunting, team, platinum, targeted, attacks, south, southeast, asia, btz, ten, journey, strategic, llc, manual, dupuy, gelsemium, route, sednit, part, observing, comings, goings, references, launchagent, launchd, jobs, initiating, ips, repeat, an1120, cron, transfers, where, same, destination, reappears, predictable, an1119, initiated, processes, exhibiting, regularity, destinations, an1118, recurrent, det0399, systems, that, identify, mitigate, level, often, unique, indicators, within, obfuscation, particular, different, across, various, families, versions, construct, way, avoid, common, defensive, m1031, mitigation, contacts, configuration, s0668, instructed, s0444, pause, s1019, s0596, given, number, seconds, s0223, configure, work, frames, s1100, sends, stolen, s0409, creates, through, attackers, frequency, compromised, hosts, s0211, exfiltrate, nighttime, s0395, communicate, s0265, reconnect, s0283, computer, identifier, string, g0126, ability, wait, between, communicating, executing, commands, s0696, run, would, make, harder, distinguish, s0200, been, programmed, outside, local, business, monday, friday, s0126, beacon, payload, reach, arbitrary, random, s0154, itself, before, requesting, s0667, collects, compresses, encrypts, exfiltrates, s0045, procedure, examples, live, permalink, 2025, last, modified, created, linux, macos, platforms, tactic, other, apply, well, alternative, protocol, channel, schedule, performed, times, day, this, could, done, blend, availability, home, open, join, mclean, hotel, location, details, found, register, here, search, blog, contribute, benefactors, legal, branding, history, engage, advisory, council, learn, more, about, get, started, detections,


Text of the page (random words):
scheduled transfer technique t1029 enterprise mitre att ck matrices enterprise mobile ics tactics enterprise mobile ics techniques enterprise mobile ics defenses mitigations enterprise mobile ics assets detections detection strategies analytics data components cti groups software campaigns resources get started learn more about att ck att ck advisory council att ckcon att ck data tools faq engage with att ck version history updates legal branding benefactors contribute blog search att ckcon 7 0 in person tickets are open join us october 27 28 2026 in mclean va register here for in person tickets hotel and location details can be found in the faq home techniques enterprise scheduled transfer scheduled transfer adversaries may schedule data exfiltration to be performed only at certain times of day or at certain intervals this could be done to blend traffic patterns with normal activity or availability when scheduled exfiltration is used other exfiltration techniques likely apply as well to transfer the information out of the network such as exfiltration over c2 channel or exfiltration over alternative protocol id t1029 sub techniques no sub techniques ⓘ tactic exfiltration ⓘ platforms linux windows macos version 1 1 created 31 may 2017 last modified 24 october 2025 version permalink live version procedure examples id name description s0045 advstoreshell advstoreshell collects compresses encrypts and exfiltrates data to the c2 server every 10 minutes 1 s0667 chrommme chrommme can set itself to sleep before requesting a new command from c2 2 s0154 cobalt strike cobalt strike can set its beacon payload to reach out to the c2 server on an arbitrary and random interval 3 s0126 comrat comrat has been programmed to sleep outside local business hours 9 to 5 monday to friday 4 s0200 dipsind dipsind can be configured to only run during normal working hours which would make its communications harder to distinguish from normal traffic 5 s0696 flagpro flagpro has the ability to wait for a specified time interval between communicating with and executing commands from c2 6 g0126 higaisa higaisa sent the victim computer identifier in a user agent string back to the c2 server every 10 minutes 7 s0283 jrat jrat can be configured to reconnect at certain intervals 8 s0265 kazuar kazuar can sleep for a specific time and be set to communicate at specific intervals 9 s0395 lightneuron lightneuron can be configured to exfiltrate data during nighttime or working hours 10 s0211 linfo linfo creates a backdoor through which remote attackers can change the frequency at which compromised hosts contact remote c2 infrastructure 11 s0409 machete machete sends stolen data to the c2 server every 10 minutes 12 s1100 ninja ninja can configure its agent to work only in specific time frames 13 s0223 powerstats powerstats can sleep for a given number of seconds 14 s0596 shadowpad shadowpad has sent data back to c2 every 8 hours 15 s1019 shark shark can pause c2 communications for a specified time 16 s0444 shimrat shimrat can sleep when instructed to do so by the c2 17 s0668 tinyturla tinyturla contacts its c2 based on a scheduled timing set in its configuration 18 mitigations id mitigation description m1031 network intrusion prevention network intrusion detection and prevention systems that use network signatures to identify traffic for specific adversary command and control infrastructure and malware can be used to mitigate activity at the network level signatures are often for unique indicators within protocols and may be based on the specific obfuscation technique used by a particular adversary or tool and will likely be different across various malware families and versions adversaries will likely change tool command and control signatures over time or construct protocols in such a way to avoid detection by common defensive tools 19 detection strategy id name analytic id analytic description det0399 detection strategy for scheduled transfer and recurrent exfiltration patterns an1118 recurring network exfiltration initiated by scheduled or script based processes exhibiting time based regularity and consistent external destinations an1119 detection of cron based or script based recurring transfers where the same script user or destination reappears at predictable intervals an1120 launchagent or launchd recurring jobs initiating data transfer to consistent external ips or domains with repeat timing signatures references eset 2016 october en route with sednit part 2 observing the comings and goings retrieved november 21 2016 dupuy t and faou m 2021 june gelsemium retrieved november 30 2021 strategic cyber llc 2017 march 14 cobalt strike manual retrieved may 24 2017 faou m 2020 may from agent btz to comrat v4 a ten year journey retrieved june 15 2020 windows defender advanced threat hunting team 2016 april 29 platinum targeted attacks in south and southeast asia retrieved february 15 2018 hada h 2021 december 28 flagpro the new malware used by blacktech retrieved march 25 2022 pt esc threat intelligence 2020 june 4 covid 19 and new year greetings an investigation into the tools and methods used by the higaisa group retrieved march 2 2021 kamluk v gostev a 2016 february adwind a cross platform rat retrieved april 23 2019 levene b et al 2017 may 03 kazuar multiplatform espionage backdoor with api access retrieved july 17 2018 faou m 2019 may turla lightneuron one email away from remote code execution retrieved june 24 2019 zhou r 2012 may 15 backdoor linfo retrieved february 23 2018 eset 2019 july machete just got sharper venezuelan government institutions under attack retrieved september 13 2019 dedola g 2022 june 21 apt toddycat retrieved january 3 2024 singh s et al 2018 march 13 iranian threat group updates tactics techniques and procedures in spear phishing campaign retrieved april 11 2018 great 2017 august 15 shadowpad in corporate networks retrieved march 22 2021 clearsky cyber security 2021 august new iranian espionage campaign by siamesekitten lyceum retrieved june 6 2022 yonathan klijnsma 2016 may 17 mofang a politically motivated information stealing adversary retrieved may 12 2020 cisco talos 2021 september 21 tinyturla turla deploys new malware to keep a secret backdoor on victim machines retrieved december 2 2021 gardiner j cova m nagaraja s 2014 february command control understanding denying and detecting retrieved april 20 2016 core objects all core att ck objects all none matrices tactics techniques sub techniques defenses all defenses all none mitigations assets detection strategies analytics data components cti all cti all none groups software campaigns reference all reference all none resources domains all domains all none enterprise mobile ics reset filters contact us terms of use privacy policy website changelog cookie preferences 2015 2026 the mitre corporation mitre att ck and att ck are registered trademarks of the mitre corporation
Thumbnail images (randomly selected): * Images may be subject to copyright.GREEN status (no comments)
  • External site

Verified site has: 65 subpage(s). Do you want to verify them? Verify pages:

1-5 6-10 11-15 16-20 21-25 26-30 31-35 36-40 41-45 46-50
51-55 56-60 61-65


The site also has references to the 1 subdomain(s)

  mitre.org  Verify


Top 50 hastags from of all verified websites.

Supplementary Information (add-on for SEO geeks)*- See more on header.verify-www.com

Header

HTTP/1.1 301 Moved Permanently
Connection close
Content-Length 162
Server GitHub.com
Content-Type text/html
Location htt????/attack.mitre.org/techniques/T1029
X-GitHub-Request-Id 22B6:09E9:8E268:988C4:6A7FF18A
x-github-edge-region uksouth
Accept-Ranges bytes
Age 0
Date Sat, 15 Aug 2026 04:56:43 GMT
Via 1.1 varnish
X-Served-By cache-lcy-egml8630082-LCY
X-Cache MISS
X-Cache-Hits 0
X-Timer S1786769803.040821,VS0,VE81
Vary Accept-Encoding
X-Fastly-Request-ID adb48809c6be1d4db44ce60bb141715e1bf7c2c5
HTTP/2 301
server GitHub.com
content-type text/html
x-origin-cache HIT
location htt????/attack.mitre.org/techniques/T1029/
access-control-allow-origin *
expires Sat, 15 Aug 2026 05:06:43 GMT
cache-control max-age=600
x-proxy-cache MISS
x-github-request-id D93A:164B5F:183B55E:185F976:6A7FF188
x-github-edge-region fra
accept-ranges bytes
age 0
date Sat, 15 Aug 2026 04:56:43 GMT
via 1.1 varnish
x-served-by cache-rtm-ehrd2290035-RTM
x-cache MISS
x-cache-hits 0
x-timer S1786769803.153326,VS0,VE103
vary Accept-Encoding
x-fastly-request-id 99132e379cd4166c184db26fdcb51f1c7c96ccb7
content-length 162
HTTP/2 200
server GitHub.com
content-type text/html; charset=utf-8
x-origin-cache HIT
last-modified Fri, 07 Aug 2026 14:24:19 GMT
access-control-allow-origin *
etag W/ 6a75ea93-f6c2
expires Sat, 15 Aug 2026 05:06:43 GMT
cache-control max-age=600
content-encoding gzip
x-proxy-cache MISS
x-github-request-id 5C9A:175124:18D592D:18F9DFD:6A7FF18A
x-github-edge-region fra
accept-ranges bytes
age 0
date Sat, 15 Aug 2026 04:56:43 GMT
via 1.1 varnish
x-served-by cache-rtm-ehrd2290035-RTM
x-cache MISS
x-cache-hits 0
x-timer S1786769803.266407,VS0,VE107
vary Accept-Encoding
x-fastly-request-id 91e2db114dfb1c04b4b21c99d88b55c592697eb5
content-length 10448

Meta Tags

title="Scheduled Transfer, Technique T1029 - Enterprise | MITRE ATT&CK®"
name="google-site-verification" content="2oJKLqNN62z6AOCb0A0IXGtbQuj-lev5YPAHFF_cbHQ"
charset="utf-8"
name="viewport" content="width=device-width, initial-scale=1,shrink-to-fit=no"
http-equiv="X-UA-Compatible" content="IE=edge"

Load Info

page size10448
load time (s)0.816028
redirect count2
speed download12803
server IP 185.199.108.153
* all occurrences of the string "http://" have been changed to "htt???/"