---
title: "Can’t Touch This: Data Exfiltration via Finger"
url: https://daily.dev/posts/can-t-touch-this-data-exfiltration-via-finger-bm5hns2nb
source_url: https://www.huntress.com/blog/cant-touch-this-data-exfiltration-via-finger
type: article
source: "Huntress Blog"
published: 2026-05-31T07:43:06.957Z
updated: 2026-05-31T08:09:15.261Z
tags: ["windows", "data-exfiltration"]
reading_time: 4
upvotes: 0
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Can’t Touch This: Data Exfiltration via Finger

**[Huntress Blog](https://daily.dev/sources/huntress-blog)** · 4 min read · 0 upvotes · 0 comments

## Summary

Huntress analysts observed a rarely-seen data exfiltration technique using finger.exe, a native Windows utility originally designed for querying remote user information. A threat actor who had created a webshell on an MS Exchange server used finger.exe to send directory listings and process names to a remote IP via TCP port 79, effectively bypassing security monitoring by blending in with legitimate-looking activity. The technique was first documented in a 2020 advisory by security researcher John Page. The post maps the activity to MITRE ATT&CK techniques T1105 and T1048.003, and recommends monitoring or removing unused LOLBins to reduce attack surface.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.huntress.com/blog/cant-touch-this-data-exfiltration-via-finger>

---

Tags: [#windows](https://daily.dev/tags/windows), [#data-exfiltration](https://daily.dev/tags/data-exfiltration)

[View this post on daily.dev](https://daily.dev/posts/can-t-touch-this-data-exfiltration-via-finger-bm5hns2nb)
