Official Description

Adversaries may exfiltrate data to a code repository rather than over their primary command and control channel. Code repositories are often accessible via an API (ex: https://api.github.com). Access to these APIs are often over HTTPS, which gives the adversary an additional level of protection.

Exfiltration to a code repository can also provide a significant amount of cover to the adversary if it is a popular service already used by hosts within the network.
Tactics
Exfiltration
Platforms
ESXi, Linux, macOS, Windows
Parent Technique
T1567 · Exfiltration Over Web Service
MITRE Version
1.2
Last Modified
May 12, 2026

View on MITRE ATT&CK ↗