Skip to main content

Management / Monitoring / Threats / DEV

Data Exfiltration Through Tampered Metrics

CCC.Monitor.TH05

If a malicious actor is able to make changes to the metrics being collected, it could be used to encrypt and or compress sensitive data and bypass controls preventing exfiltration. The data can then be staged in the monitoring system and exfiltrated in bulk at a later point in time

Related Capabilities

IDTitleDescription
CCC.Monitoring.CP01CCC.Monitoring.CP01
CCC.Monitoring.CP11CCC.Monitoring.CP11

Related Controls

IDTitleDescription
CCC.Monitor.CN06Metrics pushed for authorised services onlyUse IAM to control which types of metrics or traces can be pushed by different system to avoid a compromised system pushing fabricated metrics about a different service

External Mappings

FrameworkIDRemarks
MITRE-ATT&CKT1560Archive Collected Data
MITRE-ATT&CKT1074Data Staged
MITRE-ATT&CKT1567Exfiltration Over Web Service