T1567 Exfiltration Over Web Service — Detection & Response
Adversaries may use an existing, legitimate external Web service to exfiltrate data rather than their primary command and control channel. Popular Web services acting as an exfiltration mechanism may give a significant amount of credibility to the adversary's activities.
Coverage at a glance
- Detections shipped
- 4
- Avg. verdict time
- < 5 min
- Data sources
- 4+
Threat context
How adversaries use T1567 Exfiltration Over Web Service — Detection & Response
Adversaries may use an existing, legitimate external Web service to exfiltrate data rather than their primary command and control channel. Popular Web services acting as an exfiltration mechanism may give a significant amount of credibility to the adversary's activities.
Exfiltration to cloud storage (T1567.002) is the dominant pattern in modern data breaches, particularly in cloud environments. Attackers with compromised cloud credentials copy sensitive data to personal S3 buckets, Google Drive accounts, or Dropbox before the account is locked down. Exfiltration to code repositories (T1567.001) is a growing vector: insiders push sensitive code or data to personal GitHub repositories. Webhook exfiltration (T1567.004) is used by attackers who have persistence in a SaaS application and configure webhooks to forward data to an attacker-controlled endpoint.
Detections ManySignal ships
Ready-to-deploy detection rules
| Rule name | Severity | Data source |
|---|---|---|
| Large Upload to Personal Cloud Storage — Proxy detects large upload to Dropbox, Box, or personal Drive User uploads significantly more data than their baseline to a personal cloud storage service. | High | Proxy / CASB |
| Bulk GitHub Push to External Repo — Large commit to a repository outside the organisation A user pushes a large volume of code to a GitHub repository that is not owned by the organisation. | High | GitHub Audit Log / Proxy |
| Cross-Account S3 Exfiltration — CopyObject to bucket in external AWS account Internal data is copied to an S3 bucket in an external (non-organisation) AWS account. | Critical | AWS CloudTrail |
| Webhook Exfiltration Signature — Webhook configured to external endpoint sends data A webhook is created in a SaaS application (Slack, Salesforce) pointing to an external endpoint and begins transmitting data. | High | SaaS Application Audit Log |
Related techniques and tactics
T1078 Valid Accounts — Detection & Response
ATT&CK Technique
T1110 Brute Force — Detection & Response
ATT&CK Technique
T1566 Phishing — Detection & Response
ATT&CK Technique
T1059 Command and Scripting Interpreter — Detection & Response
ATT&CK Technique
T1053 Scheduled Task/Job — Detection & Response
ATT&CK Technique
T1548 Abuse Elevation Control Mechanism — Detection & Response
ATT&CK Technique
T1068 Exploitation for Privilege Escalation — Detection & Response
ATT&CK Technique
T1134 Access Token Manipulation — Detection & Response
ATT&CK Technique
T1098 Account Manipulation — Detection & Response
ATT&CK Technique
T1136 Create Account — Detection & Response
ATT&CK Technique
T1556 Modify Authentication Process — Detection & Response
ATT&CK Technique
T1621 Multi-Factor Authentication Request Generation — Detection & Response
ATT&CK Technique
T1567 Exfiltration Over Web Service — Detection & Response: frequently asked questions
Can ManySignal detect exfiltration to legitimate services like Google Drive or Dropbox?
Yes, when proxy or CASB telemetry is ingested. ManySignal correlates upload volume, destination service, and user identity to detect anomalous exfiltration patterns. Baseline-driven detection is effective because exfiltration volumes typically far exceed normal usage.
See the agentic SOC in action
Watch AI agents work a real alert queue — verdicts, evidence, and confidence scores included. In-house SOC or MDR, your call.