Proprietary source code detected in outbound archive
A threat actor using the alias xpI0itrs is selling 8.46GB of data allegedly stolen from Dynatrace's internal GitHub repositories, claiming access to 246 repos through an exposed Personal Access Token — a stark reminder that source code is a prime exfiltration target. Developers routinely compress proprietary code into zip archives before sending it out, and that collection-and-staging behavior is mapped to T1005 (Data from Local System). This demo uses a synthetic archive containing sample Python and Java sources that resemble proprietary code. Proactive DLP scans outbound zip, py, and java files, matches the content against data-identification rules, and blocks the transfer before intellectual property leaves the organization.
Attack Technique
Source code exfiltration
MITRE ATT&CK
T1005 ↗Platforms
File Types
MetaDefender Capabilities
Incident Coverage
This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗