Compliance Node Overview
MITRE ATT&CK T1567.003 (Exfiltration to Text Storage Sites) is an Enterprise Exfiltration sub-technique of T1567 (Exfiltration Over Web Service). Adversaries may exfiltrate data to text storage sites instead of their primary command and control channel. Text storage sites, such as pastebin[.]com, are commonly used by developers to share code and other information. Text storage sites are often used to host malicious code for C2 communication (e.g., Stage Capabilities), but adversaries may also use these sites to exfiltrate collected data. Furthermore, paid features and encryption options may allow adversaries to conceal and store data more securely. Affected platforms: Linux, macOS, Windows. MITRE-documented mitigations include M1021 Restrict Web-Based Content. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-04, AC-06, AC-16, AC-17, AC-20, AC-23.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1567/003/
SHA-256 integrity: b0b2b1191fda0be0363919dabfe2dd153fbe4cd6fac89663dd8afc945d488a2d
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1567.003: Exfiltration to Text Storage Sites (https://attack.mitre.org/techniques/T1567/003/)
- MITRE ATT&CK Tactic TA0010: Exfiltration (https://attack.mitre.org/tactics/TA0010/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access