Skip to main content

Management / Logging / Threats / DEV

Unauthorized Data Transfer Out of a Trusted Boundary

CCC.Logging.TH02

Sensitive log data, including PII, financial transaction details, or system vulnerabilities, is exfiltrated directly from the logging service's query or API interfaces by authorized but malicious insiders or compromised accounts exploiting legitimate access.

Related Capabilities

IDTitleDescription
CCC.Core.CP06Access ControlThe service automatically enforces user configurations to restrict or allow access to a specific component or a child resource based on factors such as user identities, roles, groups, or attributes.
CCC.Core.CP14API AccessThe service exposes a port enabling external actors to interact programmatically with the service and its resources using HTTP protocol methods such as GET, POST, PUT, and DELETE.
CCC.Core.CP22Location Lock-InThe service may be configured to restrict the deployment of child resources to specific geographic locations.

Related Controls

IDTitleDescription
CCC.Logging.CN06Detect and Alert on Potential Log ExfiltrationIdentify and alert on anomalous data access patterns that may indicate an attempt to exfiltrate log data.

External Mappings

FrameworkIDRemarks
MITRE-ATT&CKT1048Exfiltration Over Alternative Protocol
MITRE-ATT&CKT1567Exfiltration Over Web Service
MITRE-ATT&CKT1020Automated Exfiltration