T1567 - Exfiltration Over Web Service

Tactics:
Exfiltration
Platforms:
ESXi Linux macOS Office Suite +2
Detection:
Not specified
Description:
Adversaries may use an existing, legitimate external Web service to exfiltrate data rather than their primary command and control channel. Popular Web services acting as an exfiltration mechanism may give a significant amount of cover due to the likelihood that hosts within a network are already communicating with them prior to compromise. Firewall rules may also already exist to permit traffic to these services.

Web service providers also commonly use SSL/TLS encryption, giving adversaries an added level of protection.
Sub-techniques (4)
ID ATT&CK Actions
T1567.001 Exfiltration to Code Repository
T1567.002 Exfiltration to Cloud Storage
T1567.003 Exfiltration to Text Storage Sites
T1567.004 Exfiltration Over Webhook
Metadata
MITRE ID: T1567
STIX ID: attack-pattern--40597f16-0963-...
Platforms: ESXi, Linux, macOS, Office Suite, SaaS, Windows
Created: 13/01/2026 17:48
Updated: 06/03/2026 16:00