Cross-source coverage

T1071 / ATT&CK

Application Layer Protocol

1042 rules · 869 families across 12 sources.

312 deprecated hidden · include 5683 atomic-IOC hidden · include

From MITRE ATT&CK 19.2

Adversaries may communicate using OSI application layer protocols to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.

Adversaries may utilize many different protocols, including those used for web browsing, transferring files, electronic mail, DNS, or publishing/subscribing. For connections that occur internally within an enclave (such as those between a proxy or pivot node and other nodes), commonly used protocols are SMB, SSH, or RDP.

Platforms
Linux · macOS · Windows · Network Devices · ESXi
Telemetry
NSM:FlowWinEventLog:Sysmonauditd:SYSCALLmacos:osquerymacos:unifiedlog

How MITRE says to detect it DET0444

Detection of Command and Control Over Application Layer Protocols

Windows Analytic 1225

Detects suspicious usage of common application-layer protocols (e.g., HTTP, HTTPS, DNS, SMB) by abnormal processes, with high outbound byte counts or irregular ports, possibly indicating command and control or data exfiltration.

  • NSM:Flow http, dns, smb, ssl logs
  • WinEventLog:Sysmon EventCode=3, 22

Linux Analytic 1226

Detects suspicious curl, wget, or custom socket traffic that leverages DNS, HTTPS, or IRC-style protocols with unbalanced traffic or beacon-like intervals.

  • NSM:Flow dns, ssl, conn
  • auditd:SYSCALL execve

macOS Analytic 1227

Detects applications using abnormal protocols or high volume traffic not previously associated with the process image, such as Automator or AppleScript invoking curl or python sockets.

  • macos:osquery socket_events
  • macos:unifiedlog log stream

Network Devices Analytic 1228

Detects application-layer tunneling or unauthorized app protocols like DNS-over-HTTPS, embedded C2 in TLS/HTTP headers, or misused SMB traffic crossing VLANs.

  • NSM:Flow conn.log, http.log, dns.log, ssl.log

Sub-techniques with coverage

Counted in the 1042 above — a rule tagged a sub-technique covers this technique too.


Emerging Threats Open

711 rules · 540 families
Detection Severity Format
ET MALWARE 123Stealer Obfuscated CnC Exfil (POST) M1 Critical Suricata
ET MALWARE ACR/Amatera Stealer CnC Exfil (POST) M1 2 variants Critical Suricata
ET MALWARE ACR/Amatera Stealer CnC Exfil (POST) M2 2 variants Critical Suricata
ET MALWARE Agent Tesla Payload Request (GET) Critical Suricata
ET MALWARE Amadey CnC Response Critical Suricata
ET MALWARE AMOS CnC Exfiltration - /p2p (POST) M2 Critical Suricata
ET MALWARE AMOS Stealer CnC Checkin (POST) Critical Suricata
ET MALWARE [ANY.RUN] MetaStealer v.5 (MC-NMF TLS Server Certificate) Critical Suricata
ET MALWARE APT36 Victim Beacon M1 2 variants Critical Suricata
ET MALWARE APT36 Victim Beacon M2 2 variants Critical Suricata

+ 701 more from Emerging Threats Open → showing the 10 highest-severity

elastic/protections-artifacts

97 rules
Detection Severity Format
At Utility Launched through Udevadm Undefined Elastic TOML
Background Task Execution via a Hidden Process Undefined Elastic TOML
Bind Shell via Netcat Traditional Undefined Elastic TOML
Bind Shell via Node Undefined Elastic TOML
Bind Shell via Socket Undefined Elastic TOML
Command Interpreter with IP Address Argument Undefined Elastic TOML
Connection to a Suspicious URL Undefined Elastic TOML
Connection to Dynamic DNS Provider by an Unsigned Binary Undefined Elastic TOML
Connection to Dynamic DNS Provider by a Signed Binary Proxy Undefined Elastic TOML
Connection to WebService by an Unsigned Binary Undefined Elastic TOML

+ 87 more from elastic/protections-artifacts → showing the 10 highest-severity

elastic/detection-rules

94 rules
Detection Severity Format
Cobalt Strike Command and Control Beacon High Elastic TOML
Default Cobalt Strike Team Server Certificate High Elastic TOML
Entra ID Protection - Risk Detection - Sign-in Risk High Elastic TOML
Entra ID Protection - Risk Detection - User Risk High Elastic TOML
Halfbaked Command and Control Beacon High Elastic TOML
Machine Learning Detected DGA activity using a known SUNBURST DNS domain High Elastic TOML
Network Activity to a Suspicious Top Level Domain High Elastic TOML
Outlook Home Page Registry Modification High Elastic TOML
Possible FIN7 DGA Command and Control Behavior High Elastic TOML
Potential Meterpreter Reverse Shell High Elastic TOML

+ 84 more from elastic/detection-rules → showing the 10 highest-severity

SigmaHQ/sigma

45 rules
Detection Severity Format
OilRig APT Activity Critical Sigma
OilRig APT Registry Persistence Critical Sigma
OilRig APT Schedule Task Persistence - Security Critical Sigma
OilRig APT Schedule Task Persistence - System Critical Sigma
Silence.EDA Detection Critical Sigma
Suspicious Cobalt Strike DNS Beaconing - DNS Client Critical Sigma
APT40 Dropbox Tool User Agent High Sigma
APT User Agent High Sigma
Bitsadmin to Uncommon IP Server Address High Sigma
Bitsadmin to Uncommon TLD High Sigma

+ 35 more from SigmaHQ/sigma → showing the 10 highest-severity

splunk/security_content

33 rules
Detection Severity Format
Cisco Secure Firewall - Blacklisted SSL Certificate Fingerprint Undefined SPL
Cisco Secure Firewall - Connection to File Sharing Domain Undefined SPL
Cisco Secure Firewall - High EVE Threat Confidence Undefined SPL
Cisco Secure Firewall - High Priority Intrusion Classification Undefined SPL
Cisco Secure Firewall - High Volume of Intrusion Events Per Host Undefined SPL
Cisco Secure Firewall - Wget or Curl Download Undefined SPL
Detect Outbound SMB Traffic Undefined SPL
DNS Kerberos Coercion Undefined SPL
Excessive DNS Failures Undefined SPL
HTTP C2 Framework User Agent Undefined SPL

+ 23 more from splunk/security_content → showing the 10 highest-severity

socfortress/Wazuh-Rules

20 rules
Detection Severity Format
Command to stop the cbdaemon service detected: systemctl stop cbdaemon.service High Wazuh XML
Command to stop the falcon-sensor service detected: systemctl disable falcon-sensor or systemctl disable falcon-sensor.service High Wazuh XML
Command to stop the falcon-sensor service detected: systemctl stop falcon-sensor or systemctl stop falcon-sensor.service High Wazuh XML
Powershell script: Network object creation detected High Wazuh XML
Sysmon - Event 1: Process creation · Curl with Suspicious User-Agent (T1071.001) High Wazuh XML
Sysmon - Event 1: Process creation · PowerShell DNS C2 Script Execution (T1071.004) High Wazuh XML
Sysmon - Event 1: Process creation · PowerShell with Suspicious User-Agent (T1071.001) High Wazuh XML
Sysmon - Event 1: Process creation · Telnet C2 Client Execution (T1071) High Wazuh XML
Sysmon - Event 7: Image loaded by · Telnet C2 DLL Load (T1071) High Wazuh XML
Use of curl with custom User-Agent (MITRE T1071.001 - C2 over HTTP) High Wazuh XML

+ 10 more from socfortress/Wazuh-Rules → showing the 10 highest-severity

Azure/Azure-Sentinel

16 rules
Detection Severity Format
Europium - Hash and IP IOCs - September 2022 High KQL
First-Time Network Connection by Unusual Process High KQL
Known Forest Blizzard group domains - July 2019 High KQL
Mercury - Domain, Hash and IP IOCs - August 2022 High KQL
RunningRAT request parameters High KQL
IP address of Windows host encoded in web request Medium KQL
Malformed user agent Medium KQL
Risky user signin observed in non-Microsoft network device Medium KQL
Windows host username encoded in base64 web request Medium KQL
Fortinet - Beacon pattern detected Low KQL

+ 6 more from Azure/Azure-Sentinel → showing the 10 highest-severity

Wazuh Core Ruleset

9 rules
Detection Severity Format
ProFTPD: Attempt to bypass firewall that can't adequately keep state of FTP traffic. Critical Wazuh XML
Invalid DNS packet. Possibility of attack. High Wazuh XML
MS-FTP: Multiple FTP errors from same source. High Wazuh XML
Cisco eStreamer: APP-DETECT DNS request for potential malware Medium Wazuh XML
PHP web attack. Medium Wazuh XML
Amazon Security Lake - Route 53 - Failed DNS request for a Non-Existent Domain [] "" from . · query.type = \.*, rcode = NXDOMAIN Low Wazuh XML
Amazon Security Lake - Route 53 - Failed DNS request [] "" from . · query.type = \.*, rcode_id = -1 Low Wazuh XML
Amazon Security Lake - Route 53 - Succsessful DNS request [] "" from . · query.type = \.*, rcode = NOERROR Low Wazuh XML
osquery: : MaMi malware detected, infected DNS address · osquery.name = OSX_MaMi_DNS_Servers Low Wazuh XML

chainguard-dev/osquery-defense-kit

7 rules · 6 families
Detection Severity Format
Catch DNS traffic going to machines other than the host-configured DNS server (event-based) Undefined osquery SQL
Catch DNS traffic going to machines other than the host-configured DNS server (state-based) Undefined osquery SQL
Unexpected programs communicating over HTTPS (state-based) 2 variants Undefined osquery SQL
Unexpected programs communicating over HTTPS (state-based) 2 variants Undefined osquery SQL
Unexpected programs communicating over non-HTTPS protocols (state-based) Undefined osquery SQL
Unexpected programs communicating over non-HTTPS running from weird locations Undefined osquery SQL
Unexpected socket events Undefined osquery SQL

panther-labs/panther-analysis

5 rules
Detection Severity Format
Azure Storage Account HTTPS-Only Traffic Disabled High Panther Python
DNS request to denylisted domain High Panther Python
OpenAI Anomalous API Key Activity Medium Panther Python
VPC Flow Logs Unapproved Outbound DNS Traffic Medium Panther Python
Slack Anomaly Detected Low Panther Python

Bert-JanP/Hunting-Queries-Detection-Rules

3 rules
Detection Severity Format
MITRE ATT&CK Mapping Undefined KQL
Potential Beaconing Activity Undefined KQL
Sliver C2 Beacon Loaded Undefined KQL

chronicle/detection-rules

2 rules
Detection Severity Format
aws_guardduty_black_hole_traffic_detected High YARA-L
aws_guardduty_command_and_control_activity_detected High YARA-L

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.