Cross-source coverage
T1001 / ATT&CK
Data Obfuscation
131 rules · 82 families across 6 sources.
Showing deprecated and atomic-IOC rules · back to the default
From MITRE ATT&CK 19.2
Adversaries may obfuscate command and control traffic to make it more difficult to detect. Command and control (C2) communications are hidden (but not necessarily encrypted) in an attempt to make the content more difficult to discover or decipher and to make the communication less conspicuous and hide commands from being seen. This encompasses many methods, such as adding junk data to protocol traffic, using steganography, or impersonating legitimate protocols.
- Tactics
- Command and Control
- Platforms
- ESXi · Linux · macOS · Windows
- Telemetry
-
NSM:Flowauditd:SYSCALLmacos:unifiedlog
How MITRE says to detect it DET0053
Detect Obfuscated C2 via Network Traffic Analysis
Windows Analytic 0144
Detects excessive outbound traffic to remote host over HTTP(S) from uncommon or previously unseen processes.
NSM:FlowHTTP
Linux Analytic 0145
Identifies custom or previously unseen userland processes initiating high-volume HTTP connections with low response volume.
auditd:SYSCALLconnect
macOS Analytic 0146
Flags unexpected user applications initiating long-lived HTTP(S) sessions with irregular traffic patterns.
macos:unifiedlognetwork flowmacos:unifiedlogprocess
Sub-techniques with coverage
Counted in the 131 above — a rule tagged a sub-technique covers this technique too.
Emerging Threats Open
121 rules · 72 families| Detection | Severity | Format |
|---|---|---|
| ET MALWARE Cobalt Strike Malleable C2 (Amazon Profile) | Critical | Suricata |
| ET MALWARE Cobalt Strike Malleable C2 (Google Drive Profile) | Critical | Suricata |
| ET MALWARE Cobalt Strike Malleable C2 (MSNBC Video Profile) | Critical | Suricata |
| ET MALWARE Cobalt Strike Malleable C2 (Pandora Profile) | Critical | Suricata |
| ET DELETED Hash - Suspected Cobalt Strike Malleable C2 (ja3s) M1 | High | Suricata |
| ET JA3 Hash - Possible Cobalt Strike Server 2 variants | High | Suricata |
| ET JA3 Hash - Possible Cobalt Strike Server 2 variants | High | Suricata |
| ET JA3 Hash - Suspected Cobalt Strike Malleable C2 M1 (set) | High | Suricata |
| ET MALWARE Cobalt Strike Activity (GET) 23 variants | High | Suricata |
| ET MALWARE Cobalt Strike Activity (GET) 23 variants | High | Suricata |
+ 111 more from Emerging Threats Open → showing the 10 highest-severity
socfortress/Wazuh-Rules
4 rules| Detection | Severity | Format |
|---|---|---|
| Script executed from hidden payload likely appended to image (Stego + Execution) | High | Wazuh XML |
| Suspicious command used in possible steganographic payload delivery (T1001.002) | High | Wazuh XML |
| Sysmon - Event 1: Process creation · PowerShell Creating Tar File (T1001.002) | High | Wazuh XML |
| Sysmon - Event 1: Process creation · PowerShell with Extract-Invoke-PSImage (T1001.002) | High | Wazuh XML |
SigmaHQ/sigma
2 rules| Detection | Severity | Format |
|---|---|---|
| Suspicious LDAP-Attributes Used | High | Sigma |
| ADSI-Cache File Creation By Uncommon Tool | Medium | Sigma |
splunk/security_content
2 rules| Detection | Severity | Format |
|---|---|---|
| Windows PowGoop Beacon Decoding | Undefined | SPL |
| Windows Suspicious QEMU Execution | Undefined | SPL |
Azure/Azure-Sentinel
1 rule| Detection | Severity | Format |
|---|---|---|
| Abnormally Large JPEG Filed Downloaded from New Source | Undefined | KQL |
Wazuh Core Ruleset
1 rule| Detection | Severity | Format |
|---|---|---|
| Replace Malicious code: Malicious code in the connection was replaced. | Medium | Wazuh XML |