Suspicious curl POST Exfiltration of Archive from tmp Staging Folder via process_creation

PremiumReviewedSigma · High · v1
Product
macos
Category
process_creation
Author
HuntRule
Published
2026-09-30
Updated
2026-09-30

ATT&CK techniques

Collection → Exfiltration
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. C2

  12. Impact

What it detects

This rule detects curl invoked with an HTTP POST that uploads a file staged under the /tmp directory. A macOS infostealer collected stolen data into a /tmp staging folder and used curl to POST the resulting archive to its C2, so a curl POST referencing a /tmp file indicates active exfiltration of harvested data.

Related detections9 linkedT1041 — drag to rearrange
Suspicious Credential Archive Staging in tmp via process_creation
Restic Backup Tool Exfiltration to Cloud Object Storage
Malicious Phishing Data Exfiltration to SheetBest API by GitBait Campaign (via proxy)
Suspicious CloudScout hxkz_zip Exfiltration Archive Creation via File System
Malicious PowerShell Base64 Exfiltration to save.php via EKZ Stealer
Malicious NPM Backdoor C2 Beacon to Injective Telemetry Endpoint via Proxy
Suspicious Infostealer C2 Heartbeat to bot heartbeat Endpoint
Suspicious Exfiltration of Environment File via wget POST
Suspicious Data Exfiltration via curl Multipart Upload to Gate Endpoint
Suspicious curl POST Exfiltration of Archive from tmp Staging Folder via process_creation
Pivot detection · T1041 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.