Cross-source coverage

T1001 / ATT&CK

Data Obfuscation

113 rules · 76 families across 6 sources.

18 deprecated hidden · include

Showing atomic-IOC rules · back to the default

From MITRE ATT&CK 19.2

Adversaries may obfuscate command and control traffic to make it more difficult to detect. Command and control (C2) communications are hidden (but not necessarily encrypted) in an attempt to make the content more difficult to discover or decipher and to make the communication less conspicuous and hide commands from being seen. This encompasses many methods, such as adding junk data to protocol traffic, using steganography, or impersonating legitimate protocols.

Platforms
ESXi · Linux · macOS · Windows
Telemetry
NSM:Flowauditd:SYSCALLmacos:unifiedlog

How MITRE says to detect it DET0053

Detect Obfuscated C2 via Network Traffic Analysis

Windows Analytic 0144

Detects excessive outbound traffic to remote host over HTTP(S) from uncommon or previously unseen processes.

  • NSM:Flow HTTP

Linux Analytic 0145

Identifies custom or previously unseen userland processes initiating high-volume HTTP connections with low response volume.

  • auditd:SYSCALL connect

macOS Analytic 0146

Flags unexpected user applications initiating long-lived HTTP(S) sessions with irregular traffic patterns.

  • macos:unifiedlog network flow
  • macos:unifiedlog process

Sub-techniques with coverage

Counted in the 113 above — a rule tagged a sub-technique covers this technique too.


Emerging Threats Open

103 rules · 66 families
Detection Severity Format
ET MALWARE Cobalt Strike Malleable C2 (Amazon Profile) Critical Suricata
ET MALWARE Cobalt Strike Malleable C2 (Google Drive Profile) Critical Suricata
ET MALWARE Cobalt Strike Malleable C2 (MSNBC Video Profile) Critical Suricata
ET MALWARE Cobalt Strike Malleable C2 (Pandora Profile) Critical Suricata
ET JA3 Hash - Possible Cobalt Strike Server 2 variants High Suricata
ET JA3 Hash - Possible Cobalt Strike Server 2 variants High Suricata
ET JA3 Hash - Suspected Cobalt Strike Malleable C2 M1 (set) High Suricata
ET MALWARE Cobalt Strike Activity (GET) 13 variants High Suricata
ET MALWARE Cobalt Strike Activity (GET) 13 variants High Suricata
ET MALWARE Cobalt Strike Activity (GET) 13 variants High Suricata

+ 93 more from Emerging Threats Open → showing the 10 highest-severity

socfortress/Wazuh-Rules

4 rules
Detection Severity Format
Script executed from hidden payload likely appended to image (Stego + Execution) High Wazuh XML
Suspicious command used in possible steganographic payload delivery (T1001.002) High Wazuh XML
Sysmon - Event 1: Process creation · PowerShell Creating Tar File (T1001.002) High Wazuh XML
Sysmon - Event 1: Process creation · PowerShell with Extract-Invoke-PSImage (T1001.002) High Wazuh XML

SigmaHQ/sigma

2 rules
Detection Severity Format
Suspicious LDAP-Attributes Used High Sigma
ADSI-Cache File Creation By Uncommon Tool Medium Sigma

splunk/security_content

2 rules
Detection Severity Format
Windows PowGoop Beacon Decoding Undefined SPL
Windows Suspicious QEMU Execution Undefined SPL

Azure/Azure-Sentinel

1 rule
Detection Severity Format
Abnormally Large JPEG Filed Downloaded from New Source Undefined KQL

Wazuh Core Ruleset

1 rule
Detection Severity Format
Replace Malicious code: Malicious code in the connection was replaced. Medium Wazuh XML

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.