Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0053 — Detect Obfuscated C2 via Network Traffic Analysis
DET0053

Detect Obfuscated C2 via Network Traffic Analysis

3 analytic(s) · 1 technique(s) detected

Analytics

3
AN0144 Analytic 0144
Windows

Detects excessive outbound traffic to remote host over HTTP(S) from uncommon or previously unseen processes.

NSM:Flow HTTP
[OutboundByteThreshold] Defines threshold ratio of outbound to inbound bytes that signals possible obfuscation
[ProcessAllowlist] List of known legitimate network clients to exclude from anomaly checks
AN0145 Analytic 0145
Linux

Identifies custom or previously unseen userland processes initiating high-volume HTTP connections with low response volume.

auditd:SYSCALL connect
[UserProcessBaseline] Defines what is considered abnormal for a user-initiated process context
AN0146 Analytic 0146
macOS

Flags unexpected user applications initiating long-lived HTTP(S) sessions with irregular traffic patterns.

macos:unifiedlog network flow macos:unifiedlog process
[SessionDuration] Session length that exceeds average per-user expectations

Detected Techniques

1

Command & Control (1)

Details

MITRE ID
DET0053
STIX ID
x-mitre-detection-strategy--e17b2809-7534-4749-9bd8-95fdb24e4891
Analytics
3
Techniques Detected
1
By Tactic
Command & Control
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.