GCP bigquery.jobs.insert
Submits a BigQuery query, load, extract, or copy job.
The adversary is trying to steal data.
Exfiltration consists of techniques that adversaries may use to steal data from your network. Once they’ve collected data, adversaries often package it to avoid detection while removing it. This can include compression and encryption. Techniques for getting data out of a target network typically include transferring it over their command and control channel or an alternate channel and may also include putting size limits on the transmission.
In cloud environments, adversaries exfiltrate data by sharing snapshots or AMIs with external accounts, copying data to attacker-controlled storage buckets, or transferring resources across regions. They may also abuse cloud-native data transfer services or modify bucket policies to allow public access.
View Exfiltration on MITRE ATT&CK →Explore this tactic in the map.
Submits a BigQuery query, load, extract, or copy job.
Requests a Cloud SQL export to Cloud Storage.
Requests a server-side copy of an Azure blob.
Copies an S3 object to another key or bucket.
Requests export of Azure SQL Database schema and data to a BACPAC in Blob Storage.
Changes sharing attributes of a manual RDS DB snapshot.
Changes an AMI attribute, including launch permissions for other accounts.
Changes EBS snapshot attributes, including volume-creation permissions.
Creates or replaces an S3 bucket resource policy.
Creates or replaces an S3 bucket replication configuration.
Service event indicating use of a shared EBS snapshot to initiate a copy.
Service event indicating use of a shared EBS snapshot to create a volume.
Starts an RDS data export to Amazon S3.