Cross-source coverage
T1041 / ATT&CK
Exfiltration Over C2 Channel
712 rules · 644 families across 9 sources.
154 deprecated hidden · include 334 atomic-IOC hidden · include
From MITRE ATT&CK 19.2
Adversaries may steal data by exfiltrating it over an existing command and control channel. Stolen data is encoded into the normal communications channel using the same protocol as command and control communications.
- Tactics
- Exfiltration
- Platforms
- ESXi · Linux · macOS · Windows
- Telemetry
-
WinEventLog:SysmonNSM:FlowWinEventLog:Securityauditd:SYSCALLmacos:unifiedlogmacos:osqueryesxi:vpxaesxi:vmkernelesxi:syslog
How MITRE says to detect it DET0348
Detection Strategy for Exfiltration Over C2 Channel
Windows Analytic 0988
Identifies suspicious outbound traffic volume mismatches from processes that typically do not generate network activity, particularly over C2 protocols like HTTPS, DNS, or custom TCP/UDP ports, following file or data access.
WinEventLog:SysmonEventCode=1WinEventLog:SysmonEventCode=3, 22NSM:FlowFlow/PCAP analysis for outbound payloadsWinEventLog:SecurityEventCode=4663, 4670, 4656
Linux Analytic 0989
Monitors for processes reading sensitive files then immediately initiating unusual outbound connections or bulk transfer sessions over persistent sockets, particularly with encrypted or binary payloads.
auditd:SYSCALLexecveauditd:SYSCALLconnectNSM:Flowconn.log + files.log + ssl.logNSM:Flowsession stats with bytes_out > bytes_in
macOS Analytic 0990
Detects unauthorized applications or scripts accessing sensitive data followed by establishing encrypted outbound communication to rare external destinations or with abnormal byte ratios.
macos:unifiedlogeventMessage = 'open', 'sendto', 'connect'macos:osquerysocket_eventsmacos:osqueryprocess_events
ESXi Analytic 0991
Detects VMs sending outbound traffic through non-standard services or to unknown destinations. Exfiltration over reverse shells tunneled via VMkernel or custom payloads routed via hostd/vpxa.
esxi:vpxaconnection attempts and data transmission logsesxi:vmkernelnetwork stack module logsesxi:syslogguest OS outbound transfer logs
Emerging Threats Open
662 rules · 595 families| Detection | Severity | Format |
|---|---|---|
| ET MALWARE DeskRAT CnC Command Inbound (Upload_execute) | Critical | Suricata |
| ET MALWARE DeskRAT CnC HeartBeat Request | Critical | Suricata |
| ET MALWARE DeskRAT Victim HeartBeat Response | Critical | Suricata |
| ET MALWARE SainboxRAT CnC Checkin | Critical | Suricata |
| ET MALWARE SVCStealer CnC Checkin Confirmation | Critical | Suricata |
| ET MALWARE UNK_MonkeyWrench Exfil via SMTP | Critical | Suricata |
| ET ADWARE_PUP Nivesro Cheat CnC Activity M1 | High | Suricata |
| ET ADWARE_PUP NivesroCheat CnC Activity M2 | High | Suricata |
| ET ADWARE_PUP RelevantKnowledge Adware CnC Beacon | High | Suricata |
| ET CURRENT_EVENTS [Fireeye] Backdoor.DNS.BEACON.[CSBundle DNS] | High | Suricata |
+ 652 more from Emerging Threats Open → showing the 10 highest-severity
elastic/detection-rules
18 rules| Detection | Severity | Format |
|---|---|---|
| DNS Tunneling | Low | Elastic TOML |
| Network Activity Detected via Kworker | Low | Elastic TOML |
| Network Traffic to Rare Destination Country | Low | Elastic TOML |
| Potential Data Exfiltration Activity to an Unusual Destination Port | Low | Elastic TOML |
| Potential Data Exfiltration Activity to an Unusual IP Address | Low | Elastic TOML |
| Potential Data Exfiltration Activity to an Unusual ISO Code | Low | Elastic TOML |
| Potential Data Exfiltration Activity to an Unusual Region | Low | Elastic TOML |
| Spike in Firewall Denies | Low | Elastic TOML |
| Spike in host-based traffic | Low | Elastic TOML |
| Spike in Network Traffic | Low | Elastic TOML |
+ 8 more from elastic/detection-rules → showing the 10 highest-severity
splunk/security_content
10 rules| Detection | Severity | Format |
|---|---|---|
| Cisco ASA - Device File Copy to Remote Location | Undefined | SPL |
| Cisco Secure Firewall - High EVE Threat Confidence | Undefined | SPL |
| Cisco Secure Firewall - Intrusion Events by Threat Activity | Undefined | SPL |
| Cisco Secure Firewall - Lumma Stealer Download Attempt | Undefined | SPL |
| Cisco Secure Firewall - Lumma Stealer Outbound Connection Attempt | Undefined | SPL |
| Cisco Secure Firewall - Potential Data Exfiltration | Undefined | SPL |
| Detect SNICat SNI Exfiltration | Undefined | SPL |
| Potential Telegram API Request Via CommandLine | Undefined | SPL |
| Windows Exfiltration Over C2 Via Invoke RestMethod | Undefined | SPL |
| Windows Exfiltration Over C2 Via Powershell UploadString | Undefined | SPL |
panther-labs/panther-analysis
8 rules · 7 families| Detection | Severity | Format |
|---|---|---|
| Snowflake Data Exfiltration 2 variants | Critical | Panther Python |
| Snowflake Data Exfiltration 2 variants | Critical | Panther Python |
| GCP K8S Pod Create Or Modify Host Path Volume Mount | High | Panther Python |
| Kubernetes Pod With HostPath Volume Mount | Medium | Panther Python |
| Auth0 Delete Tenant Member | Informational | Panther Python |
| Snowflake File Downloaded | Informational | Panther Python |
| Snowflake Table Copied Into Stage | Informational | Panther Python |
| Snowflake Temporary Stage Created | Informational | Panther Python |
SigmaHQ/sigma
5 rules| Detection | Severity | Format |
|---|---|---|
| Equation Group C2 Communication | High | Sigma |
| OpenCanary - TFTP Request | High | Sigma |
| Shai-Hulud NPM Package Malicious Exfiltration via Curl | High | Sigma |
| Network Communication Initiated To Portmap.IO Domain | Medium | Sigma |
| Tunneling Tool Execution | Medium | Sigma |
Azure/Azure-Sentinel
4 rules| Detection | Severity | Format |
|---|---|---|
| RunningRAT request parameters | High | KQL |
| IP address of Windows host encoded in web request | Medium | KQL |
| Windows host username encoded in base64 web request | Medium | KQL |
| External IP address in Command Line | Undefined | KQL |
socfortress/Wazuh-Rules
3 rulesWazuh Core Ruleset
1 rule| Detection | Severity | Format |
|---|---|---|
| Security group with inbound rules allowing "Unknown cidrIp" on port "Unknown port" detected. | High | Wazuh XML |
chronicle/detection-rules
1 rule| Detection | Severity | Format |
|---|---|---|
| sap_suspected_data_exfiltration | Medium | YARA-L |