T1567

Exfiltration Over Web Service

Index entry

In-depth coverage of this technique (how it looks in telemetry, how to hunt it, and how to rule out benign activity) is coming soon. It's in our catalog and on the roadmap to be written up.

View this technique on MITRE ATT&CK →

Practice it

1 scenario in this catalog covers T1567. We don't name it — identifying the technique is part of what a scenario grades. Explore the dashboard →