What MITRE ATT&CK T1567: Exfiltration Over Web Service (Exfiltration) requires
MITRE ATT&CK T1567 covers adversary exfiltration of stolen data via legitimate web services (cloud storage, code-sharing sites, paste sites) to blend with normal SaaS use. Sub-techniques: Exfiltration to Code Repository (T1567.001), Exfiltration to Cloud Storage (T1567.002), Exfiltration to Text Storage Sites (T1567.003), Exfiltration over Webhook (T1567.004). The 2023-2024 Cl0p MOVEit campaign used this pattern at scale. Compliance: NIST 800-53 SC-7, AC-4, ISO 27001 A.8.12, A.8.16, GDPR Article 32-33, PCI DSS Req 11.4.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1567/
SHA-256 integrity: 520701fe14e640242991f6032690a64b4a5498d45a575c88abed5a64c32806f5
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1567: Exfiltration Over Web Service (https://attack.mitre.org/techniques/T1567/) with 4 sub-techniques
- NIST SP 800-53 Rev 5: SC-7 including SC-7(10), AC-4
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.