Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0058 — Detection Strategy for Web Service: Dead Drop Resolver
DET0058

Detection Strategy for Web Service: Dead Drop Resolver

4 analytic(s) · 1 technique(s) detected

Analytics

4
AN0158 Analytic 0158
Windows

Detection of a process or script that accesses a common web service to retrieve content containing obfuscated indicators of a secondary C2 server (dead drop resolver behavior).

WinEventLog:Sysmon EventCode=3, 22 etw:Microsoft-Windows-NDIS-PacketCapture TLS Handshake/Network Flow
[TargetDomain] FQDN or IP for the hosting site of the dead drop (e.g., pastebin.com, twitter.com)
[TimeWindow] Defines how close in time the suspicious network and process behavior must occur
[UserContext] Filter by user or system accounts to reduce noise
AN0159 Analytic 0159
Linux

Detection of a process or script that accesses a common web service to retrieve content containing obfuscated indicators of a secondary C2 server (dead drop resolver behavior).

auditd:SYSCALL connect NSM:Flow HTTP/TLS Logs
[TargetDomain] Dead drop hosting domain (e.g., GitHub, Google Docs)
[PayloadEntropyThreshold] Detects high entropy in payloads signaling obfuscation
[TimeWindow] Causal proximity between access to resolver and follow-up connections
AN0160 Analytic 0160
macOS

Detection of a process or script that accesses a common web service to retrieve content containing obfuscated indicators of a secondary C2 server (dead drop resolver behavior).

macos:unifiedlog subsystem: com.apple.network macos:osquery process_events/socket_events
[TargetService] Known services abused for D2 (e.g., iCloud, Dropbox)
[UserContext] Useful to isolate rare users accessing web services for C2
[TimeWindow] Max time gap between dead drop resolver fetch and follow-on traffic
AN0161 Analytic 0161
ESXi

Detection of a process or script that accesses a common web service to retrieve content containing obfuscated indicators of a secondary C2 server (dead drop resolver behavior).

esxi:vobd Network Events NSM:Firewall Outbound Connections
[DestinationIP] Identifies unusual IP destinations embedded in traffic
[Protocol] Used to detect uncommon protocols (e.g., DNS over HTTPS)
[TimeWindow] Used to correlate outbound web requests with process execution

Detected Techniques

1

Command & Control (1)

Details

MITRE ID
DET0058
STIX ID
x-mitre-detection-strategy--70abbe3f-797d-495b-8f76-371408a0f929
Analytics
4
Techniques Detected
1
By Tactic
Command & Control
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.