T1020

Automated Exfiltration

Linux · macOS · Network Devices · Windowsnothing on this site yetT1020 on attack.mitre.org

Adversaries may exfiltrate data, such as sensitive documents, through the use of automated processing after being gathered during Collection. When automated exfiltration is used, other exfiltration techniques likely apply as well to transfer the information out of the network, such as Exfiltration Over C2 Channel and Exfiltration Over Alternative Protocol.

MITRE ATT&CK 19.2, retrieved 2026-09-12

If this is happening now

1

Checklists and playbooks to open while the alert is still live.

how MITRE says to see it

Automated Exfiltration Detection Strategy

  • Detection of automated tools or scripts periodically transmitting data to external destinations using scheduled tasks or background processes.
  • Background scripts (e.g., via cron) or daemons transmitting data repeatedly to remote IPs or URLs.
  • Observation of LaunchAgents or LaunchDaemons establishing periodic external connections indicative of automated data transfer.

sub-techniques

The description, detection analytics and mitigations are reproduced from MITRE ATT&CK, version 19.2, under its terms of use. The checklists, hunts, labs and everything else linked here are this site’s.