Compliance Node Overview
MITRE ATT&CK T1567.004 (Exfiltration Over Webhook) is an Enterprise Exfiltration sub-technique of T1567 (Exfiltration Over Web Service). Adversaries may exfiltrate data to a webhook endpoint rather than over their primary command and control channel. Webhooks are simple mechanisms for allowing a server to push data over HTTP/S to a client without the need for the client to continuously poll the server. Many public and commercial services, such as Discord, Slack, and webhook.site, support the creation of webhook endpoints that can be used by other services, such as Github, Jira, or Trello. Affected platforms: Windows, macOS, Linux, SaaS, Office Suite. MITRE-documented mitigations include M1057 Data Loss Prevention. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-04, AC-06, AC-16, AC-17, AC-20, AC-23.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1567/004/
SHA-256 integrity: 1b8597b428005b1a969e16d2d399b60c72313f19a38990c6fd3e220d4df65eff
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1567.004: Exfiltration Over Webhook (https://attack.mitre.org/techniques/T1567/004/)
- MITRE ATT&CK Tactic TA0010: Exfiltration (https://attack.mitre.org/tactics/TA0010/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access