Possible Data Exfiltration to Discord Webhook Endpoint (via proxy)

PremiumReviewedSigma · Medium · v1
Category
proxy
Author
HuntRule
Published
2026-09-13
Updated
2026-09-13

ATT&CK techniques

Exfiltration
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Impact

What it detects

This rule detects outbound web requests to a Discord webhook API path which the Empyrean stealer and many commodity stealers use to exfiltrate stolen credentials and tokens. Requests to this endpoint from non messaging applications warrant investigation.

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.