M ManySignal
T1567 MITRE ATT&CK

T1567 Exfiltration Over Web Service — Detection & Response

Adversaries may use an existing, legitimate external Web service to exfiltrate data rather than their primary command and control channel. Popular Web services acting as an exfiltration mechanism may give a significant amount of credibility to the adversary's activities.

Coverage at a glance

Detections shipped
4
Avg. verdict time
< 5 min
Data sources
4+

Threat context

How adversaries use T1567 Exfiltration Over Web Service — Detection & Response

Adversaries may use an existing, legitimate external Web service to exfiltrate data rather than their primary command and control channel. Popular Web services acting as an exfiltration mechanism may give a significant amount of credibility to the adversary's activities.

Exfiltration to cloud storage (T1567.002) is the dominant pattern in modern data breaches, particularly in cloud environments. Attackers with compromised cloud credentials copy sensitive data to personal S3 buckets, Google Drive accounts, or Dropbox before the account is locked down. Exfiltration to code repositories (T1567.001) is a growing vector: insiders push sensitive code or data to personal GitHub repositories. Webhook exfiltration (T1567.004) is used by attackers who have persistence in a SaaS application and configure webhooks to forward data to an attacker-controlled endpoint.

Detections ManySignal ships

Ready-to-deploy detection rules

Rule name Severity Data source

Large Upload to Personal Cloud Storage — Proxy detects large upload to Dropbox, Box, or personal Drive

User uploads significantly more data than their baseline to a personal cloud storage service.

High Proxy / CASB

Bulk GitHub Push to External Repo — Large commit to a repository outside the organisation

A user pushes a large volume of code to a GitHub repository that is not owned by the organisation.

High GitHub Audit Log / Proxy

Cross-Account S3 Exfiltration — CopyObject to bucket in external AWS account

Internal data is copied to an S3 bucket in an external (non-organisation) AWS account.

Critical AWS CloudTrail

Webhook Exfiltration Signature — Webhook configured to external endpoint sends data

A webhook is created in a SaaS application (Slack, Salesforce) pointing to an external endpoint and begins transmitting data.

High SaaS Application Audit Log

T1567 Exfiltration Over Web Service — Detection & Response: frequently asked questions

Can ManySignal detect exfiltration to legitimate services like Google Drive or Dropbox?

Yes, when proxy or CASB telemetry is ingested. ManySignal correlates upload volume, destination service, and user identity to detect anomalous exfiltration patterns. Baseline-driven detection is effective because exfiltration volumes typically far exceed normal usage.

See the agentic SOC in action

Watch AI agents work a real alert queue — verdicts, evidence, and confidence scores included. In-house SOC or MDR, your call.