Cross-source coverage

T1041 / ATT&CK

Exfiltration Over C2 Channel

712 rules · 644 families across 9 sources.

154 deprecated hidden · include 334 atomic-IOC hidden · include

From MITRE ATT&CK 19.2

Adversaries may steal data by exfiltrating it over an existing command and control channel. Stolen data is encoded into the normal communications channel using the same protocol as command and control communications.

Tactics
Exfiltration
Platforms
ESXi · Linux · macOS · Windows
Telemetry
WinEventLog:SysmonNSM:FlowWinEventLog:Securityauditd:SYSCALLmacos:unifiedlogmacos:osqueryesxi:vpxaesxi:vmkernelesxi:syslog

How MITRE says to detect it DET0348

Detection Strategy for Exfiltration Over C2 Channel

Windows Analytic 0988

Identifies suspicious outbound traffic volume mismatches from processes that typically do not generate network activity, particularly over C2 protocols like HTTPS, DNS, or custom TCP/UDP ports, following file or data access.

  • WinEventLog:Sysmon EventCode=1
  • WinEventLog:Sysmon EventCode=3, 22
  • NSM:Flow Flow/PCAP analysis for outbound payloads
  • WinEventLog:Security EventCode=4663, 4670, 4656

Linux Analytic 0989

Monitors for processes reading sensitive files then immediately initiating unusual outbound connections or bulk transfer sessions over persistent sockets, particularly with encrypted or binary payloads.

  • auditd:SYSCALL execve
  • auditd:SYSCALL connect
  • NSM:Flow conn.log + files.log + ssl.log
  • NSM:Flow session stats with bytes_out > bytes_in

macOS Analytic 0990

Detects unauthorized applications or scripts accessing sensitive data followed by establishing encrypted outbound communication to rare external destinations or with abnormal byte ratios.

  • macos:unifiedlog eventMessage = 'open', 'sendto', 'connect'
  • macos:osquery socket_events
  • macos:osquery process_events

ESXi Analytic 0991

Detects VMs sending outbound traffic through non-standard services or to unknown destinations. Exfiltration over reverse shells tunneled via VMkernel or custom payloads routed via hostd/vpxa.

  • esxi:vpxa connection attempts and data transmission logs
  • esxi:vmkernel network stack module logs
  • esxi:syslog guest OS outbound transfer logs

Emerging Threats Open

662 rules · 595 families
Detection Severity Format
ET MALWARE DeskRAT CnC Command Inbound (Upload_execute) Critical Suricata
ET MALWARE DeskRAT CnC HeartBeat Request Critical Suricata
ET MALWARE DeskRAT Victim HeartBeat Response Critical Suricata
ET MALWARE SainboxRAT CnC Checkin Critical Suricata
ET MALWARE SVCStealer CnC Checkin Confirmation Critical Suricata
ET MALWARE UNK_MonkeyWrench Exfil via SMTP Critical Suricata
ET ADWARE_PUP Nivesro Cheat CnC Activity M1 High Suricata
ET ADWARE_PUP NivesroCheat CnC Activity M2 High Suricata
ET ADWARE_PUP RelevantKnowledge Adware CnC Beacon High Suricata
ET CURRENT_EVENTS [Fireeye] Backdoor.DNS.BEACON.[CSBundle DNS] High Suricata

+ 652 more from Emerging Threats Open → showing the 10 highest-severity

elastic/detection-rules

18 rules
Detection Severity Format
DNS Tunneling Low Elastic TOML
Network Activity Detected via Kworker Low Elastic TOML
Network Traffic to Rare Destination Country Low Elastic TOML
Potential Data Exfiltration Activity to an Unusual Destination Port Low Elastic TOML
Potential Data Exfiltration Activity to an Unusual IP Address Low Elastic TOML
Potential Data Exfiltration Activity to an Unusual ISO Code Low Elastic TOML
Potential Data Exfiltration Activity to an Unusual Region Low Elastic TOML
Spike in Firewall Denies Low Elastic TOML
Spike in host-based traffic Low Elastic TOML
Spike in Network Traffic Low Elastic TOML

+ 8 more from elastic/detection-rules → showing the 10 highest-severity

splunk/security_content

10 rules
Detection Severity Format
Cisco ASA - Device File Copy to Remote Location Undefined SPL
Cisco Secure Firewall - High EVE Threat Confidence Undefined SPL
Cisco Secure Firewall - Intrusion Events by Threat Activity Undefined SPL
Cisco Secure Firewall - Lumma Stealer Download Attempt Undefined SPL
Cisco Secure Firewall - Lumma Stealer Outbound Connection Attempt Undefined SPL
Cisco Secure Firewall - Potential Data Exfiltration Undefined SPL
Detect SNICat SNI Exfiltration Undefined SPL
Potential Telegram API Request Via CommandLine Undefined SPL
Windows Exfiltration Over C2 Via Invoke RestMethod Undefined SPL
Windows Exfiltration Over C2 Via Powershell UploadString Undefined SPL

panther-labs/panther-analysis

8 rules · 7 families
Detection Severity Format
Snowflake Data Exfiltration 2 variants Critical Panther Python
Snowflake Data Exfiltration 2 variants Critical Panther Python
GCP K8S Pod Create Or Modify Host Path Volume Mount High Panther Python
Kubernetes Pod With HostPath Volume Mount Medium Panther Python
Auth0 Delete Tenant Member Informational Panther Python
Snowflake File Downloaded Informational Panther Python
Snowflake Table Copied Into Stage Informational Panther Python
Snowflake Temporary Stage Created Informational Panther Python

SigmaHQ/sigma

5 rules
Detection Severity Format
Equation Group C2 Communication High Sigma
OpenCanary - TFTP Request High Sigma
Shai-Hulud NPM Package Malicious Exfiltration via Curl High Sigma
Network Communication Initiated To Portmap.IO Domain Medium Sigma
Tunneling Tool Execution Medium Sigma

Azure/Azure-Sentinel

4 rules
Detection Severity Format
RunningRAT request parameters High KQL
IP address of Windows host encoded in web request Medium KQL
Windows host username encoded in base64 web request Medium KQL
External IP address in Command Line Undefined KQL

socfortress/Wazuh-Rules

3 rules
Detection Severity Format
Sysmon - Event 1: Process creation · DNS tunneling via Resolve-DnsName (T1041) High Wazuh XML
Sysmon - Event 1: Process creation · PowerShell HTTP POST to C2 (T1041) High Wazuh XML
Sysmon - Event 1: Process creation · win.eventdata.image = powershell.exe$|pwsh.exe, win.eventdata.commandLine = Start-BitsTransfer|Invoke-WebRequest|iwr -Uri|WebClient|wge… High Wazuh XML

Wazuh Core Ruleset

1 rule
Detection Severity Format
Security group with inbound rules allowing "Unknown cidrIp" on port "Unknown port" detected. High Wazuh XML

chronicle/detection-rules

1 rule
Detection Severity Format
sap_suspected_data_exfiltration Medium YARA-L

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.