MITRE ATT&CK Enterprise
T1567

Exfiltration Over Web Service

Description

Adversaries may use an existing, legitimate external Web service to exfiltrate data rather than their primary command and control channel. Popular Web services acting as an exfiltration mechanism may give a significant amount of cover due to the likelihood that hosts within a network are already communicating with them prior to compromise. Firewall rules may also already exist to permit traffic to these services. Web service providers also commonly use SSL/TLS encryption, giving adversaries an added level of protection.

Mapped SPARTA techniques

1 techniques

  • EXF-0008Compromised Developer SiteST0008
    addresses
    moderate

    T1567 'Exfiltration Over Web Service' addresses exfiltration via cloud/web services that are common in development environments (Git hosts, artifact repos, cloud storage); SPARTA EXF-0008 'Compromised Developer Site' covers exactly this pattern (theft of source, test vectors, build artifacts, telemetry captures via the dev environment's web-service infrastructure). Tactic and activity align.

Cross-framework references

Relationships published by the source frameworks themselves, reproduced here with attribution. They are not SafeMode Space mappings and carry no confidence rating of ours.

Cite as SafeMode Space, mitre-attack-enterprise T1567.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.