1200KM / simulation
T1567.004 Exfiltration Over Webhook — Attack Simulation
Adversaries may exfiltrate data to a webhook endpoint rather than over their primary command and control channel. Webhooks are simple mechanisms for allowing a server to push data over HTTP/S to a client without the need for the client to continuously poll the server. Many public and commercial services, such as Discord, Slack, and `webhook.site`, support the creation of webhook endpoints that can be used by other services, such as Github, Jira,…
Technique description
Adversaries may exfiltrate data to a webhook endpoint rather than over their primary command and control channel. Webhooks are simple mechanisms for allowing a server to push data over HTTP/S to a client without the need for the client to continuously poll the server. Many public and commercial services, such as Discord, Slack, and `webhook.site`, support the creation of webhook endpoints that can be used by other services, such as Github, Jira,…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Exfiltrate staged data to a Microsoft Teams webhook (PowerShell)
Procedure 35ad6590-2207-4b14-bf8f-9899470d7156; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Exfiltrate staged file to a Discord webhook with curl (bash)
Procedure 40c44d16-bb49-4d14-aafa-f9ba7e6e6c5b; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Exfiltrate staged data to a Slack webhook with curl (sh)
Procedure c666acd6-6ff5-4d28-9490-195d89cd4337; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Exfiltrate staged data to a Discord webhook (PowerShell)
Procedure f0057c81-24dc-4a2e-b658-5809c242180b; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
No reviewed association in this snapshot.
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.