Cross-source coverage
T1071 / ATT&CK
Application Layer Protocol
1042 rules · 869 families across 12 sources.
312 deprecated hidden · include 5683 atomic-IOC hidden · include
From MITRE ATT&CK 19.2
Adversaries may communicate using OSI application layer protocols to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.
Adversaries may utilize many different protocols, including those used for web browsing, transferring files, electronic mail, DNS, or publishing/subscribing. For connections that occur internally within an enclave (such as those between a proxy or pivot node and other nodes), commonly used protocols are SMB, SSH, or RDP.
- Tactics
- Command and Control
- Platforms
- Linux · macOS · Windows · Network Devices · ESXi
- Telemetry
-
NSM:FlowWinEventLog:Sysmonauditd:SYSCALLmacos:osquerymacos:unifiedlog
How MITRE says to detect it DET0444
Detection of Command and Control Over Application Layer Protocols
Windows Analytic 1225
Detects suspicious usage of common application-layer protocols (e.g., HTTP, HTTPS, DNS, SMB) by abnormal processes, with high outbound byte counts or irregular ports, possibly indicating command and control or data exfiltration.
NSM:Flowhttp, dns, smb, ssl logsWinEventLog:SysmonEventCode=3, 22
Linux Analytic 1226
Detects suspicious curl, wget, or custom socket traffic that leverages DNS, HTTPS, or IRC-style protocols with unbalanced traffic or beacon-like intervals.
NSM:Flowdns, ssl, connauditd:SYSCALLexecve
macOS Analytic 1227
Detects applications using abnormal protocols or high volume traffic not previously associated with the process image, such as Automator or AppleScript invoking curl or python sockets.
macos:osquerysocket_eventsmacos:unifiedloglog stream
Network Devices Analytic 1228
Detects application-layer tunneling or unauthorized app protocols like DNS-over-HTTPS, embedded C2 in TLS/HTTP headers, or misused SMB traffic crossing VLANs.
NSM:Flowconn.log, http.log, dns.log, ssl.log
Sub-techniques with coverage
Counted in the 1042 above — a rule tagged a sub-technique covers this technique too.
Emerging Threats Open
711 rules · 540 families| Detection | Severity | Format |
|---|---|---|
| ET MALWARE 123Stealer Obfuscated CnC Exfil (POST) M1 | Critical | Suricata |
| ET MALWARE ACR/Amatera Stealer CnC Exfil (POST) M1 2 variants | Critical | Suricata |
| ET MALWARE ACR/Amatera Stealer CnC Exfil (POST) M2 2 variants | Critical | Suricata |
| ET MALWARE Agent Tesla Payload Request (GET) | Critical | Suricata |
| ET MALWARE Amadey CnC Response | Critical | Suricata |
| ET MALWARE AMOS CnC Exfiltration - /p2p (POST) M2 | Critical | Suricata |
| ET MALWARE AMOS Stealer CnC Checkin (POST) | Critical | Suricata |
| ET MALWARE [ANY.RUN] MetaStealer v.5 (MC-NMF TLS Server Certificate) | Critical | Suricata |
| ET MALWARE APT36 Victim Beacon M1 2 variants | Critical | Suricata |
| ET MALWARE APT36 Victim Beacon M2 2 variants | Critical | Suricata |
+ 701 more from Emerging Threats Open → showing the 10 highest-severity
elastic/protections-artifacts
97 rules| Detection | Severity | Format |
|---|---|---|
| At Utility Launched through Udevadm | Undefined | Elastic TOML |
| Background Task Execution via a Hidden Process | Undefined | Elastic TOML |
| Bind Shell via Netcat Traditional | Undefined | Elastic TOML |
| Bind Shell via Node | Undefined | Elastic TOML |
| Bind Shell via Socket | Undefined | Elastic TOML |
| Command Interpreter with IP Address Argument | Undefined | Elastic TOML |
| Connection to a Suspicious URL | Undefined | Elastic TOML |
| Connection to Dynamic DNS Provider by an Unsigned Binary | Undefined | Elastic TOML |
| Connection to Dynamic DNS Provider by a Signed Binary Proxy | Undefined | Elastic TOML |
| Connection to WebService by an Unsigned Binary | Undefined | Elastic TOML |
+ 87 more from elastic/protections-artifacts → showing the 10 highest-severity
elastic/detection-rules
94 rules| Detection | Severity | Format |
|---|---|---|
| Cobalt Strike Command and Control Beacon | High | Elastic TOML |
| Default Cobalt Strike Team Server Certificate | High | Elastic TOML |
| Entra ID Protection - Risk Detection - Sign-in Risk | High | Elastic TOML |
| Entra ID Protection - Risk Detection - User Risk | High | Elastic TOML |
| Halfbaked Command and Control Beacon | High | Elastic TOML |
| Machine Learning Detected DGA activity using a known SUNBURST DNS domain | High | Elastic TOML |
| Network Activity to a Suspicious Top Level Domain | High | Elastic TOML |
| Outlook Home Page Registry Modification | High | Elastic TOML |
| Possible FIN7 DGA Command and Control Behavior | High | Elastic TOML |
| Potential Meterpreter Reverse Shell | High | Elastic TOML |
+ 84 more from elastic/detection-rules → showing the 10 highest-severity
SigmaHQ/sigma
45 rules| Detection | Severity | Format |
|---|---|---|
| OilRig APT Activity | Critical | Sigma |
| OilRig APT Registry Persistence | Critical | Sigma |
| OilRig APT Schedule Task Persistence - Security | Critical | Sigma |
| OilRig APT Schedule Task Persistence - System | Critical | Sigma |
| Silence.EDA Detection | Critical | Sigma |
| Suspicious Cobalt Strike DNS Beaconing - DNS Client | Critical | Sigma |
| APT40 Dropbox Tool User Agent | High | Sigma |
| APT User Agent | High | Sigma |
| Bitsadmin to Uncommon IP Server Address | High | Sigma |
| Bitsadmin to Uncommon TLD | High | Sigma |
+ 35 more from SigmaHQ/sigma → showing the 10 highest-severity
splunk/security_content
33 rules| Detection | Severity | Format |
|---|---|---|
| Cisco Secure Firewall - Blacklisted SSL Certificate Fingerprint | Undefined | SPL |
| Cisco Secure Firewall - Connection to File Sharing Domain | Undefined | SPL |
| Cisco Secure Firewall - High EVE Threat Confidence | Undefined | SPL |
| Cisco Secure Firewall - High Priority Intrusion Classification | Undefined | SPL |
| Cisco Secure Firewall - High Volume of Intrusion Events Per Host | Undefined | SPL |
| Cisco Secure Firewall - Wget or Curl Download | Undefined | SPL |
| Detect Outbound SMB Traffic | Undefined | SPL |
| DNS Kerberos Coercion | Undefined | SPL |
| Excessive DNS Failures | Undefined | SPL |
| HTTP C2 Framework User Agent | Undefined | SPL |
+ 23 more from splunk/security_content → showing the 10 highest-severity
socfortress/Wazuh-Rules
20 rules+ 10 more from socfortress/Wazuh-Rules → showing the 10 highest-severity
Azure/Azure-Sentinel
16 rules| Detection | Severity | Format |
|---|---|---|
| Europium - Hash and IP IOCs - September 2022 | High | KQL |
| First-Time Network Connection by Unusual Process | High | KQL |
| Known Forest Blizzard group domains - July 2019 | High | KQL |
| Mercury - Domain, Hash and IP IOCs - August 2022 | High | KQL |
| RunningRAT request parameters | High | KQL |
| IP address of Windows host encoded in web request | Medium | KQL |
| Malformed user agent | Medium | KQL |
| Risky user signin observed in non-Microsoft network device | Medium | KQL |
| Windows host username encoded in base64 web request | Medium | KQL |
| Fortinet - Beacon pattern detected | Low | KQL |
+ 6 more from Azure/Azure-Sentinel → showing the 10 highest-severity
Wazuh Core Ruleset
9 rules| Detection | Severity | Format |
|---|---|---|
| ProFTPD: Attempt to bypass firewall that can't adequately keep state of FTP traffic. | Critical | Wazuh XML |
| Invalid DNS packet. Possibility of attack. | High | Wazuh XML |
| MS-FTP: Multiple FTP errors from same source. | High | Wazuh XML |
| Cisco eStreamer: APP-DETECT DNS request for potential malware | Medium | Wazuh XML |
| PHP web attack. | Medium | Wazuh XML |
| Amazon Security Lake - Route 53 - Failed DNS request for a Non-Existent Domain [] "" from . · query.type = \.*, rcode = NXDOMAIN | Low | Wazuh XML |
| Amazon Security Lake - Route 53 - Failed DNS request [] "" from . · query.type = \.*, rcode_id = -1 | Low | Wazuh XML |
| Amazon Security Lake - Route 53 - Succsessful DNS request [] "" from . · query.type = \.*, rcode = NOERROR | Low | Wazuh XML |
| osquery: : MaMi malware detected, infected DNS address · osquery.name = OSX_MaMi_DNS_Servers | Low | Wazuh XML |
chainguard-dev/osquery-defense-kit
7 rules · 6 families| Detection | Severity | Format |
|---|---|---|
| Catch DNS traffic going to machines other than the host-configured DNS server (event-based) | Undefined | osquery SQL |
| Catch DNS traffic going to machines other than the host-configured DNS server (state-based) | Undefined | osquery SQL |
| Unexpected programs communicating over HTTPS (state-based) 2 variants | Undefined | osquery SQL |
| Unexpected programs communicating over HTTPS (state-based) 2 variants | Undefined | osquery SQL |
| Unexpected programs communicating over non-HTTPS protocols (state-based) | Undefined | osquery SQL |
| Unexpected programs communicating over non-HTTPS running from weird locations | Undefined | osquery SQL |
| Unexpected socket events | Undefined | osquery SQL |
panther-labs/panther-analysis
5 rules| Detection | Severity | Format |
|---|---|---|
| Azure Storage Account HTTPS-Only Traffic Disabled | High | Panther Python |
| DNS request to denylisted domain | High | Panther Python |
| OpenAI Anomalous API Key Activity | Medium | Panther Python |
| VPC Flow Logs Unapproved Outbound DNS Traffic | Medium | Panther Python |
| Slack Anomaly Detected | Low | Panther Python |
Bert-JanP/Hunting-Queries-Detection-Rules
3 rules| Detection | Severity | Format |
|---|---|---|
| MITRE ATT&CK Mapping | Undefined | KQL |
| Potential Beaconing Activity | Undefined | KQL |
| Sliver C2 Beacon Loaded | Undefined | KQL |
chronicle/detection-rules
2 rules| Detection | Severity | Format |
|---|---|---|
| aws_guardduty_black_hole_traffic_detected | High | YARA-L |
| aws_guardduty_command_and_control_activity_detected | High | YARA-L |