Skip to content

Hide Navigation Hide TOC

Direct Markdown Image/Link Exfil Payload (attacker.com / evil.com) - ATR-2026-01454 (78838bff-060b-5085-823d-19e336a265c9)

Detects markdown image and link syntax that directly embeds attacker-controlled domains (attacker.com, evil.com, exfil., collect.) with exfiltration-specific query parameters. Unlike ATR-2026-00501 (which detects instruction patterns) and ATR-2026-01453 (which detects the base64-QUERY template), this rule detects the artifact itself when it appears directly in input — e.g. a raw payload like "" or "Click here". These appear as standalone injection payloads or embedded in social-engineering text.

Cluster A Galaxy A Cluster B Galaxy B Level
Direct Markdown Image/Link Exfil Payload (attacker.com / evil.com) - ATR-2026-01454 (78838bff-060b-5085-823d-19e336a265c9) Agent Threat Rules Exfiltration via ML Inference API (b07d147f-51c8-4eb6-9a05-09c86762a9c1) MITRE ATLAS Attack Pattern 1