Adversaries may exfiltrate data to a code repository rather than over their primary command and control channel. Code repositories are often accessible via an API (ex: https://api.github.com). Access to these APIs are often over HTTPS, which gives the adversary an additional level of protection. Exfiltration to a code repository can also provide a significant amount of cover to the adversary if it is a popular service already used by hosts within the network.

Linked Issues

Issuelinks
Linktype Issue
is related to Techniques
is blocked by Detection Strategy for Exfiltration to Code Repository
is blocked by Restrict Web-Based Content
is blocked by Use of External Technology Assets, Applications and/or Services (TAAS)
is blocked by Boundary Protection
is blocked by Data Flow Enforcement – Access Control Lists (ACLs)
Impressum German English