T1567.001 - Exfiltration to Code Repository

Sub-technique
Tattiche:
Exfiltration
Piattaforme:
Linux macOS Windows ESXi
Rilevamento:
Not specified
Description:
Adversaries may exfiltrate data to a code repository rather than over their primary command and control channel. Code repositories are often accessible via an API (ex: https://api.github.com). Access to these APIs are often over HTTPS, which gives the adversary an additional level of protection.

Exfiltration to a code repository can also provide a significant amount of cover to the adversary if it is a popular service already used by hosts within the network.
Malware (1)
Metadata
MITRE ID: T1567.001
STIX ID: attack-pattern--86a96bf6-cf8b-...
Piattaforme: Linux, macOS, Windows, ESXi
Created: 13/01/2026 17:48
Updated: 06/03/2026 16:00