Skip to main content
← Back to Demos
Data Loss Prevention intermediate · 15 min

Proprietary source code detected in outbound archive

A threat actor using the alias xpI0itrs is selling 8.46GB of data allegedly stolen from Dynatrace's internal GitHub repositories, claiming access to 246 repos through an exposed Personal Access Token — a stark reminder that source code is a prime exfiltration target. Developers routinely compress proprietary code into zip archives before sending it out, and that collection-and-staging behavior is mapped to T1005 (Data from Local System). This demo uses a synthetic archive containing sample Python and Java sources that resemble proprietary code. Proactive DLP scans outbound zip, py, and java files, matches the content against data-identification rules, and blocks the transfer before intellectual property leaves the organization.

Attack Technique

Source code exfiltration

MITRE ATT&CK

T1005 ↗

Platforms

linux

File Types

.zip

MetaDefender Capabilities

Proactive DLP

Incident Coverage

This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗

--- ---