MITRE ATT&CK Enterprise
T1041

Exfiltration Over C2 Channel

Description

Adversaries may steal data by exfiltrating it over an existing command and control channel. Stolen data is encoded into the normal communications channel using the same protocol as command and control communications.

Mapped SPARTA techniques

2 techniques

  • T1041 'Exfiltration Over C2 Channel' is the ATT&CK exfiltration-tactic technique for siphoning data over the legitimate command-and-control channel; SPARTA EXF-0007 covers compromised-ground-system exfiltration where the GS's legitimate data-distribution paths (telemetry forwarders, archive databases, cross-site links) are the C2-equivalent channel. Tactic and activity align directly.

  • IMP-0006TheftST0009
    addresses
    moderate

    MITRE Enterprise has no impact-tactic data-theft technique; the theft outcome is captured through the exfiltration mechanism (T1041 Exfiltration Over C2 Channel and related). T1041 covers data theft via the legitimate C2 channel — the primary mechanism for SPARTA IMP-0006 'Theft' (steal mission-critical data via spacecraft downlink). Cross-tactic moderate (exfiltration vs impact) honors MITRE's separation of exfil-mechanism from impact-outcome where SPARTA combines them.

Cross-framework references

Relationships published by the source frameworks themselves, reproduced here with attribution. They are not SafeMode Space mappings and carry no confidence rating of ours.

Cite as SafeMode Space, mitre-attack-enterprise T1041.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.