Adversaries may use an existing, legitimate external Web service to exfiltrate data rather than their primary command and control channel. Tactics TA0010 Sub-techniques T1567.001 T1567.002 T1567.003 T1567.004 See: MITRE ATT&CK