Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0499 — Behavioral Detection of Fallback or Alternate C2 Channels
DET0499

Behavioral Detection of Fallback or Alternate C2 Channels

4 analytic(s) · 1 technique(s) detected

Analytics

4
AN1376 Analytic 1376
Windows

Establishing network connections on uncommon ports or protocols following C2 disruption or blocking. Often executed by processes that typically exhibit no network activity.

WinEventLog:Sysmon EventCode=3, 22 NSM:Flow uncommon ports
[DestinationPort] Can be tuned to include unexpected or high-entropy ports not typically associated with the process.
[ProcessName] Useful to filter benign applications vs suspicious fallback attempts.
[DataVolumeRatio] Tunable ratio of sent/received bytes to indicate potential C2 beaconing or exfiltration.
[TimeWindow] Adjust temporal window to match likely fallback C2 retries after primary channel fails.
AN1377 Analytic 1377
Linux

Creation of outbound connections on alternate ports or using covert transport (e.g., ICMP, DNS) from non-network-intensive processes, following known disruption or blocked traffic.

auditd:SYSCALL outbound connections NSM:Flow alternate ports
[ProtocolType] Can filter for rare fallback channel types (e.g., ICMP, DNS over HTTP).
[UserContext] Tuning by user (e.g., root vs. service account) helps suppress noise.
AN1378 Analytic 1378
macOS

Outbound fallback traffic from low-profile or background launch agents using unusual protocols or destinations after primary channel inactivity.

macos:unifiedlog None NSM:Flow None
[LaunchAgentContext] Used to suppress known legitimate agents.
[PayloadEntropy] Can help isolate covert or encrypted fallback traffic.
AN1379 Analytic 1379
ESXi

Outbound traffic from host management services or guest-to-host interactions over unusual interfaces (e.g., backdoor API endpoints or external VPN tunnels).

esxi:vmkernel None esxi:vpxd None
[InterfaceName] May vary based on ESXi build and should be filtered to suppress known interfaces.
[FallbackIPRanges] Environment-specific ranges to ignore (e.g., DR tunnels or out-of-band mgmt).

Detected Techniques

1

Command & Control (1)

Details

MITRE ID
DET0499
STIX ID
x-mitre-detection-strategy--ee1c44c9-c5aa-4a9c-9e68-49854ed4d602
Analytics
4
Techniques Detected
1
By Tactic
Command & Control
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.