BIOCs
Browse the Cortex behavioral indicator of compromise (BIOC) detection rules.
8 BIOCs match the current filters. tactic: TA0010 ✕ technique: T1048 ✕
Download CSV Show ATT&CK heatmapBitTorrent P2P file sharing Informational Exfiltration
The host used BitTorrent for P2P file sharing (according to the App-ID), which is typically not allowed in corporate networks and may be used to exfiltrate information.
Indicator:Network Connections app id contains *bittorrent*
ATT&CK tactics: Exfiltration (TA0010)ATT&CK techniques: Exfiltration Over Alternative Protocol (T1048)- Preventable:
- No
- Source:
- Palo Alto Networks
- Updated:
- 2026-02-11
Bitsadmin.exe used to upload data High Exfiltration
Some attacks are known to abuse BITSAdmin to hide how data upload using legitimate Windows tools.
Indicator:Process action type = execution AND target process cmd = */transfer * AND */upload * AND target process name = bitsadmin.exe
ATT&CK tactics: Exfiltration (TA0010) Defense Evasion (TA0005)ATT&CK techniques: Exfiltration Over Alternative Protocol (T1048) BITS Jobs (T1197)- Preventable:
- Yes
- Source:
- Palo Alto Networks
- Updated:
- 2026-02-11
Curl connects to an external network Informational Exfiltration
Curl is a command-line utility used to transfer data. Attackers may use curl to exfiltrate data outside your organization.
Indicator:Network action type = outgoing , failed AND remote ip != 10.* AND 172.16.* AND 172.17.* AND 172.18.* AND 172.19.* AND 172.20.* AND 172.21.* AND 172.22.* AND 172.23.* AND 172.24.* AND 172.25.* AND 172.26.* AND 172.27.* AND 172.28.* AND 172.29.* AND 172.30.* AND 172.31.* AND 192.168.* AND 127.* AND 169.254.* AND remote port != 53 AND 0 Process initiated by = curl AND cgo signer != *palo alto networks* Host host os = linux , windows
ATT&CK tactics: Exfiltration (TA0010)ATT&CK techniques: Exfiltration Over Alternative Protocol (T1048)- Preventable:
- Yes
- Source:
- Palo Alto Networks
- Updated:
- 2026-08-23
FTP/SSH client reads office files Low Exfiltration
Seeing FTP/SSH related software accessing office files could be an indication of data exfiltration.
Indicator:File file name = *.docx , *.doc , *.xlsx , *.xls , *.ppt , *.pptx AND action type = read Process initiated by = ftp.exe , putty.exe , winscp.exe , plink.exe , bash.exe , scp.exe , pscp.exe , psftp.exe
ATT&CK tactics: Exfiltration (TA0010)ATT&CK techniques: Exfiltration Over Alternative Protocol (T1048)- Preventable:
- Yes
- Source:
- Palo Alto Networks
- Updated:
- 2026-08-23
Microsoft Office spawns curl/wget on a macOS device Informational Exfiltration
Microsoft Office Word/Excel/PowerPoint/Outlook spawn wget/curl on a macOS device.
Indicator:Process action type = execution AND target process name = curl , wget Process initiated by = Microsoft Excel , Microsoft Word , Microsoft PowerPoint , Microsoft Outlook , cgo name = Microsoft Excel , Microsoft Word , Microsoft PowerPoint , Microsoft Outlook , os parent name = Microsoft Excel , Microsoft Word , Microsoft PowerPoint , Microsoft Outlook
ATT&CK tactics: Exfiltration (TA0010)ATT&CK techniques: Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted Non-C2 Protocol (T1048.003)- Preventable:
- Yes
- Source:
- Palo Alto Networks
- Updated:
- 2026-08-23
Scripting engine makes connections over DNS ports Informational Exfiltration
Scripting engine makes connections over DNS ports should not happen, as DNS traffic is typically managed by svchost and sometimes the browsers. Attackers are known to use DNS traffic to exfiltrate data and avoid detection.
Indicator:Network action type = failed , outgoing AND remote port = 53 Process os parent name = cmd.exe , powershell.exe , wscript.exe , cscript.exe , mshta.exe AND os parent signature = Signed Host host os != linux AND host os = windows
ATT&CK tactics: Exfiltration (TA0010)ATT&CK techniques: Exfiltration Over Alternative Protocol (T1048)- Preventable:
- Yes
- Source:
- Palo Alto Networks
- Updated:
- 2026-08-23
Unsigned process makes connections over DNS ports Informational Exfiltration
An unsigned process makes connections over DNS ports should not happen, as DNS traffic is typically managed by svchost and sometimes the browsers. Attackers are known to use DNS traffic to exfiltrate data and avoid detection.
Indicator:Network action type = outgoing , failed AND remote port = 53 Process os parent signature = Unsigned , N/A , Weak Hash , Invalid Signature Host host os = windows
ATT&CK tactics: Exfiltration (TA0010)ATT&CK techniques: Exfiltration Over Alternative Protocol (T1048)- Preventable:
- Yes
- Source:
- Palo Alto Networks
- Updated:
- 2026-08-23
Wget connection to an external network Informational Exfiltration
Wget is a command-line utility used to transfer data. Attackers may use wget to exfiltrate data outside your organization.
Indicator:Network action type = outgoing , failed AND remote ip != 10.* AND 172.16.* AND 172.17.* AND 172.18.* AND 172.19.* AND 172.20.* AND 172.21.* AND 172.22.* AND 172.23.* AND 172.24.* AND 172.25.* AND 172.26.* AND 172.27.* AND 172.28.* AND 172.29.* AND 172.30.* AND 172.31.* AND 192.168.* AND 127.* AND 169.254.* AND remote port != 53 AND 0 Process initiated by = wget
ATT&CK tactics: Exfiltration (TA0010)ATT&CK techniques: Exfiltration Over Alternative Protocol (T1048)- Preventable:
- Yes
- Source:
- Palo Alto Networks
- Updated:
- 2026-08-23