T1570: Lateral Tool Transfer
Adversaries may transfer tools or other files between systems in a compromised environment. Once brought into the victim environment (i.e., Ingress Tool Transfer) files may then be copied from one system to another to stage adversary tools or other files over the course of an operation.
Adversaries may copy files between internal victim systems to support lateral movement using inherent file sharing protocols such as file sharing over SMB/Windows Admin Shares to connected network shares or with authenticated connections via Remote Desktop Protocol.CitationUnit42 LockerGoga 2019
Files can also be transferred using native or otherwise present tools on the victim system, such as scp, rsync, curl, sftp, and ftp. In some cases, adversaries may be able to leverage Web Services such as Dropbox or OneDrive to copy files from one machine to another via shared, automatically synced folders.CitationDropbox Malware Sync
Security context for executives and security teams
Lateral Tool Transfer matters because it is how an intruder who already has a foothold can stage malware, utilities, scripts, or other files across internal systems to continue movement. For leaders, the key issue is not the specific tool name; it is whether internal file movement over SMB/admin shares, RDP-connected shares, scp, rsync, curl, sftp, ftp, or synced cloud folders is visible and governed. ATT&CK maps this technique to Windows, Linux, macOS, and ESXi, making it relevant to mixed enterprise and virtualization environments.
Executive priority
Prioritize this as an internal movement and resilience control question: can the organization prove which systems are allowed to exchange files, which identities can write to administrative shares or remote folders, and whether SOC/IR teams can reconstruct file movement during an incident? The relationship set links this technique to espionage, ransomware, disruptive, and electric-power-related campaigns, so coverage is especially important for organizations where lateral movement could affect critical operations, regulated evidence, or cyber-physical continuity.
Technical view
For SOC and IR teams, validate visibility across internal file transfer paths rather than only internet ingress. The ATT&CK description names SMB/Windows Admin Shares, RDP-associated file access, scp, rsync, curl, sftp, ftp, and cloud-synced folders such as Dropbox or OneDrive as possible transfer paths. Because official ATT&CK detection text is not provided, use the related detection strategy DET0183 as a starting point and test whether endpoint, network, identity, and cloud-sync telemetry can connect file creation/copy events to authenticated sessions, remote source hosts, destination hosts, and user or service accounts across Windows, Linux, macOS, and ESXi estates.
Likely telemetry
- Endpoint file creation, modification, and copy events on servers and workstations
- Process execution telemetry for native transfer utilities such as scp, rsync, curl, sftp, and ftp where present
- Windows SMB/admin share access logs and authenticated network session records
- Remote Desktop Protocol session records and evidence of redirected or shared drives where collected
- Network flow or protocol metadata for lateral file transfer traffic between internal systems
Detection direction
- Baseline legitimate administrative software distribution, backup, patching, and file replication activity before alerting on internal transfers; these are likely false-positive sources.
- Look for unusual source-destination pairs, new internal transfer paths, administrative share writes, or file staging shortly before additional lateral movement behavior.
- Correlate transfer utility execution with network connections and resulting file writes on remote systems; single-source telemetry may miss the full chain.
- Validate monitoring for cloud-synced folders because shared sync services can obscure whether a file moved through local user action or automatic synchronization.
- Confirm coverage across non-Windows platforms and ESXi where applicable; Windows-centric SMB monitoring alone will not cover all platforms listed by ATT&CK.
Mitigation priorities
- Restrict lateral file transfer paths to documented business needs using network traffic filtering, including protocol-based and firewall controls between internal segments.
- Apply network intrusion prevention where signatures or policy controls can block known unwanted transfer traffic at appropriate network boundaries.
- Limit access to administrative shares, remote file copy paths, and synchronized folders to authorized identities and managed systems.
- Segment high-value, operational, and virtualization environments so broad internal file movement is not implicitly allowed.
- Maintain auditability of approved software distribution and administrative transfer mechanisms so incident responders can distinguish normal operations from suspicious staging.
Additional notes and limits
This object is a technique, not a vulnerability or malware family. The supplied ATT&CK relationships show broad use across named campaigns and groups, including ransomware, espionage, disruptive activity, and electric-power-related campaigns, which raises its decision value for resilience planning. The most useful local validation is a tabletop or detection test that asks: if a file is copied from one compromised internal host to another, can the SOC identify the source, destination, account, protocol or tool, and resulting file?
Official ATT&CK detection guidance for T1570 is not provided in the supplied object, so detection recommendations are derived from the technique description, platforms, related DET0183 detection strategy, and listed mitigations. This take does not assert current exploitation, customer exposure, attribution, or guaranteed detection coverage. Local architecture, logging configuration, identity model, and approved administrative workflows are required to determine actual risk and control effectiveness.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Lateral Tool Transfer
Adversaries may transfer tools or other files between systems in a compromised environment. Once brought into the victim environment (i.e., Ingress Tool Transfer) files may then be copied from one system to another to stage adversary tools or other files over the course of an operation.
Adversaries may copy files between internal victim systems to support lateral movement using inherent file sharing protocols such as file sharing over SMB/Windows Admin Shares to connected network shares or with authenticated connections via Remote Desktop Protocol.CitationUnit42 LockerGoga 2019
Files can also be transferred using native or otherwise present tools on the victim system, such as scp, rsync, curl, sftp, and ftp. In some cases, adversaries may be able to leverage Web Services such as Dropbox or OneDrive to copy files from one machine to another via shared, automatically synced folders.CitationDropbox Malware Sync
How security teams should use this page
Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.
All related ATT&CK context
No relationships are available in the current normalized data for this object.
Object version and sync metadata
The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.
Mirrored ATT&CK source object
The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
