MITRE ATT&CK Enterprise
T1048

Exfiltration Over Alternative Protocol

Description

Adversaries may steal data by exfiltrating it over a different protocol than that of the existing command and control channel. The data may also be sent to an alternate network location from the main command and control server. Alternate protocols include FTP, SMTP, HTTP/S, DNS, SMB, or any other network protocol not being used as the main command and control channel. Adversaries may also opt to encrypt and/or obfuscate these alternate channels. [Exfiltration Over Alternative Protocol](https://attack.mitre.org/techniques/T1048) can be done using various common operating system utilities such as [Net](https://attack.mitre.org/software/S0039)/SMB or FTP.(Citation: Palo Alto OilRig Oct 2016) On macOS and Linux <code>curl</code> may be used to invoke protocols such as HTTP/S or FTP/S to exfiltrate data from a system.(Citation: 20 macOS Common Tools and Techniques) Many IaaS and SaaS platforms (such as Microsoft Exchange, Microsoft SharePoint, GitHub, and AWS S3) support the direct download of files, emails, source code, and other sensitive information via the web console or [Cloud API](https://attack.mitre.org/techniques/T1059/009).

Mapped SPARTA techniques

1 techniques

  • EXF-0009Compromised Partner SiteST0008
    addresses
    moderate

    T1048 'Exfiltration Over Alternative Protocol' covers exfil via non-C2 protocols (often used to bypass monitoring on the primary channel); SPARTA EXF-0009 'Compromised Partner Site' covers exfil through partner-network connections that frequently use varied protocols (DNS, ICMP, custom partner-specific protocols). Cross-domain moderate (partner-channel context vs MITRE's typical SMTP/DNS/ICMP examples).

Cross-framework references

Relationships published by the source frameworks themselves, reproduced here with attribution. They are not SafeMode Space mappings and carry no confidence rating of ours.

Cite as SafeMode Space, mitre-attack-enterprise T1048.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.