1200KM / detection
T1567.002 Exfiltration to Cloud Storage — Detection Rules
Detection workspace for T1567.002 Exfiltration to Cloud Storage: 13 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Rclone Activity via Proxy · test · medium · {"category":"proxy"}
- DNS Query for Anonfiles.com Domain - DNS Client · test · high · {"product":"windows","service":"dns-client","definition":"Requirements: Microsoft-Windows-DNS Client Events/Operational Event Log must be enabled/collected in order to receive the events."}
- DNS Query To MEGA Hosting Website - DNS Client · test · medium · {"product":"windows","service":"dns-client","definition":"Requirements: Microsoft-Windows-DNS Client Events/Operational Event Log must be enabled/collected in order to receive the events."}
- DNS Query To Ufile.io - DNS Client · test · low · {"product":"windows","service":"dns-client","definition":"Requirements: Microsoft-Windows-DNS Client Events/Operational Event Log must be enabled/collected in order to receive the events."}
- DNS Query for Anonfiles.com Domain - Sysmon · test · high · {"product":"windows","category":"dns_query"}
- DNS Query To MEGA Hosting Website · test · medium · {"product":"windows","category":"dns_query"}
- DNS Query To Ufile.io · test · low · {"product":"windows","category":"dns_query"}
- Rclone Config File Creation · test · medium · {"product":"windows","category":"file_event"}
- Suspicious Dropbox API Usage · test · high · {"category":"network_connection","product":"windows"}
- Network Connection Initiated To Mega.nz · test · low · {"category":"network_connection","product":"windows"}
- Curl File Upload To File Sharing Websites · experimental · high · {"category":"process_creation","product":"windows"}
- PUA - Rclone Execution · test · high · {"product":"windows","category":"process_creation"}
- PUA - Restic Backup Tool Execution · experimental · high · {"product":"windows","category":"process_creation"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0570 Detection Strategy for Exfiltration to Cloud Storage
AN1571 Analytic 1571
Unusual processes (e.g., powershell.exe, excel.exe) accessing large local files and subsequently initiating HTTPS POST requests to domains associated with cloud storage services (e.g., dropbox.com, drive.google.com, box.com). Defender perspective: correlation between file reads in sensitive directories and high outbound traffic volume to known storage APIs.
AN1572 Analytic 1572
Processes such as curl, wget, rclone, or custom scripts executing uploads to cloud storage endpoints. Defender perspective: detect chained events where tar/gzip is executed to compress files followed by HTTPS PUT/POST requests to known storage services.
AN1573 Analytic 1573
Applications or scripts invoking cloud storage APIs (Dropbox sync, iCloud, Google Drive client) in unexpected contexts. Defender perspective: detect sensitive file reads by non-standard applications followed by unusual encrypted uploads to external cloud storage domains.
AN1574 Analytic 1574
Unusual ESXi processes (vmx, hostd) reading datastore files and generating outbound HTTPS traffic toward external cloud storage endpoints. Defender perspective: anomalous datastore activity followed by network transfers to Dropbox, AWS S3, or other storage services.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- Turla · G0010
- Threat Group-3390 · G0027
- FIN7 · G0046
- Leviathan · G0065
- MuddyWater · G0069
- Kimsuky · G0094
- Wizard Spider · G0102
- Chimera · G0114
- Indrik Spider · G0119
- HAFNIUM · G0125
- ZIRCONIUM · G0128
- Mustang Panda · G0129
- Confucius · G0142
- HEXANE · G1001
- Ember Bear · G1003
- POLONIUM · G1005
- Earth Lusca · G1006
- LuminousMoth · G1014
- Scattered Spider · G1015
- Cinnamon Tempest · G1021
- ToddyCat · G1022
- Akira · G1024
- Medusa Group · G1051
- Contagious Interview · G1052
- Storm-0501 · G1053
Existing anomaly research
Connected anomaly research
Curated research views reached through an exact source technique, a catalog model, or a reviewed collection reference. These are navigation associations, not claims of detector effectiveness or sensor equivalence.
Telemetry contracts · Maintained query examples · Validation and blind spots
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.