A SOC analyst sees an endpoint transfer 18 GB over HTTPS to a rarely contacted external file-sharing host over 12 hours. DNS shows the same domain, but EDR finds no persistence, beaconing, or command responses. Which MITRE ATT&CK tactic best describes this activity?
Select an answer to reveal the explanation.
Short Explanation
Think of a quiet phone call as C2 and a moving truck as exfiltration. If the data is leaving, you classify the tactic by the payload's exit, not by the encrypted tunnel. That's why you tag the big HTTPS upload to a rare host as exfiltration, even if no obvious beaconing exists.
Full Explanation
MITRE ATT&CK organizes adversary behavior into tactics, which are goals, and techniques, which are methods. A large outbound HTTPS transfer to a rarely contacted external host matches Exfiltration because the observable effect is data leaving the monitored environment over a web protocol. The encrypted transport may resemble normal browsing, but the volume, destination rarity, and one-way flow are the deciding signals. Command and Control would require a channel used to direct the victim, typically with beaconing or tasking responses, rather than bulk data egress. Collection covers local gathering or staging of data before movement, so it explains what happened before the upload, not the transfer itself. Defense Evasion focuses on avoiding detection or removing evidence, such as obfuscation or log deletion, and is not the primary goal when the measurable outcome is moving sensitive data out. Exam caveat: Do not classify by encryption alone; HTTPS can carry C2, exfiltration, or benign traffic, so the tactic follows the adversary objective. Operational check: Correlate the destination with DNS and proxy logs, estimate bytes transferred, and compare the host's historical outbound baseline before escalating.