T1071 Application Layer Protocol — ATT&CK Technique
Adversaries may communicate using OSI application layer protocols to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server. Adversaries may utilize many different protocols, including those used for web browsing, transferring files, electronic mail, DNS, or publishing/subscribing. For connections that occur internally within an enclave (such as those between a proxy or pivot node and other nodes), commonly used protocols are SMB, SSH, or RDP.
Detection coverage (12)
- GALLIUM Artefacts - Builtin high
- GALLIUM IOCs high
- Suspicious Installer Package Child Process medium
- HackTool - SILENTTRINITY Stager DLL Load high
- Github Self-Hosted Runner Execution medium
- HackTool - SILENTTRINITY Stager Execution high
- Potentially Suspicious Rundll32.EXE Execution of UDL File medium
- Windows App Layer Protocol Qakbot NamedPipe
- Windows App Layer Protocol Wermgr Connect To NamedPipe
- Windows Application Layer Protocol RMS Radmin Tool Namedpipe
- Cisco Secure Firewall - High Priority Intrusion Classification
- Cisco Secure Firewall - High Volume of Intrusion Events Per Host