Compliance Node Overview
MITRE ATT&CK T1011.001 (Exfiltration Over Bluetooth) is an Enterprise Exfiltration sub-technique of T1011 (Exfiltration Over Other Network Medium). Adversaries may attempt to exfiltrate data over Bluetooth rather than the command and control channel. If the command and control network is a wired Internet connection, an adversary may opt to exfiltrate data using a Bluetooth communication channel. Adversaries may choose to do this if they have sufficient access and proximity. Bluetooth connections might not be secured or defended as well as the primary Internet-connected channel because it is not routed through the same enterprise network. Affected platforms: Linux, macOS, Windows. MITRE-documented mitigations include M1042 Disable or Remove Feature or Program, M1028 Operating System Configuration. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-18, CM-02, CM-06, CM-07, CM-08, RA-05, SC-43, SI-03.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1011/001/
SHA-256 integrity: d5016ca67735c41d32220bc61823b38cfd386a79bac740237b8e4a56008e7416
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1011.001: Exfiltration Over Bluetooth (https://attack.mitre.org/techniques/T1011/001/)
- MITRE ATT&CK Tactic TA0010: Exfiltration (https://attack.mitre.org/tactics/TA0010/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access