T1071 Application Layer Protocol
Adversaries may communicate using OSI application layer protocols to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server. Adversaries may utilize many different protocols, including those used for web browsing, transferring files,…
Quién la usa · con noticias en Jábega
Reglas Sigma para cazarla
- Ursnif Malware C2 URL Patterncriticalstable · proxy
- Cobalt Strike DNS Beaconingcriticaltest · dns
- HackTool - BabyShark Agent Default URL Patterncriticaltest · proxy
- OilRig APT Activitycriticaltest · windows
- OilRig APT Registry Persistencecriticaltest · windows
- OilRig APT Schedule Task Persistence - Securitycriticaltest · windows
- OilRig APT Schedule Task Persistence - Systemcriticaltest · windows
- PwnDrp Accesscriticaltest · proxy
- Silence.EDA Detectioncriticaltest · windows
- Suspicious Cobalt Strike DNS Beaconing - DNS Clientcriticaltest · windows
- Suspicious Cobalt Strike DNS Beaconing - Sysmoncriticaltest · windows
- Ursnif Malware Download URL Patternhighstable · proxy
- APT User Agenthightest · proxy
- APT40 Dropbox Tool User Agenthightest · proxy
- Bitsadmin to Uncommon IP Server Addresshightest · proxy
- Bitsadmin to Uncommon TLDhightest · proxy
- Chafer Malware URL Patternhightest · proxy
- ComRAT Network Communicationhightest · proxy
- Crypto Miner User Agenthightest · proxy
- DNS Exfiltration and Tunneling Tools Executionhightest · windows
- DNS TXT Answer with Possible Execution Stringshightest · dns
- Exploit Framework User Agenthightest · proxy
- GALLIUM Artefacts - Builtinhightest · windows
- GALLIUM IOCshightest · windows
- HackTool - CobaltStrike Malleable Profile Patterns - Proxyhightest · proxy
Mostrando 25 de 61.
Reglas de SigmaHQ · Detection Rule License 1.1. Técnica de MITRE ATT&CK®.