// MITRE ATT&CK

T1041 · Exfiltration Over C2 Channel

🎯 Exfiltration ESXiLinuxmacOSWindows

Adversaries may steal data by exfiltrating it over an existing command and control channel. Stolen data is encoded into the normal communications channel using the same protocol as command and control communications....

How to detect & mitigate it

Detecting Exfiltration Over C2 Channel starts with your SIEM/EDR telemetry. Write a detection rule with the Sigma generator, analyze suspicious logs in the log analyzer, and place the technique on your coverage with the ATT&CK matrix.

Related techniques

Source: MITRE ATT&CK®. ATT&CK is a registered trademark of The MITRE Corporation. Content for educational purposes.