T1048 Exfiltration Over Alternative Protocol
Adversaries may steal data by exfiltrating it over a different protocol than that of the existing command and control channel. The data may also be sent to an alternate network location from the main command and control server. Alternate protocols include FTP, SMTP, HTTP/S, DNS, SMB, or any other network protocol not being used as the main command and control channel. Adversaries may also opt to…
Quién la usa · con noticias en Jábega
Reglas Sigma para cazarla
- DNS Exfiltration and Tunneling Tools Executionhightest · windows
- Powershell DNSExfiltrationhightest · windows
- Suspicious Redirection to Local Admin Sharehightest · windows
- Suspicious WebDav Client Execution Via Rundll32.EXEhightest · windows
- PUA - Restic Backup Tool Executionhighexperimental · windows
- Copy From Or To Admin Share Or Sysvol Foldermediumtest · windows
- DNS TOR Proxiesmediumtest · zeek
- Data Exfiltration with Wgetmediumtest · linux
- Data Export From MSSQL Table Via BCP.EXEmediumtest · windows
- PowerShell ICMP Exfiltrationmediumtest · windows
- Suspicious DNS Query with B64 Encoded Stringmediumtest · dns
- Suspicious Outbound SMTP Connectionsmediumtest · windows
- Tap Driver Installationmediumtest · windows
- Tap Installer Executionmediumtest · windows
- WebDav Client Execution Via Rundll32.EXEmediumtest · windows
- Python WebServer Execution - Linuxmediumexperimental · linux
- TanStack Supply-Chain Attack DNS Indicatorsmediumexperimental · windows
Reglas de SigmaHQ · Detection Rule License 1.1. Técnica de MITRE ATT&CK®.