{"id":"T1071.002","name":"File Transfer Protocols","url":"https://attack.mitre.org/techniques/T1071/002","tactics":["command-and-control"],"platforms":["ESXi","Linux","macOS","Network Devices","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0416","stix_id":"x-mitre-detection-strategy--1fba9af9-8087-4958-90c0-ecdd8c887f6f","name":"Detection of File Transfer Protocol-Based C2 (FTP, FTPS, SMB, TFTP)","url":"https://attack.mitre.org/detectionstrategies/DET0416","analytics":[{"id":"AN1169","stix_id":"x-mitre-analytic--befbbdad-a17b-41f2-bb24-5cb477c5cc50","name":"Analytic 1169","description":"Detects FTP, SMB, or TFTP traffic initiated by suspicious processes like PowerShell, cmd.exe, or rundll32.exe—especially with large outbound file transfers or unbalanced traffic volume.","url":"https://attack.mitre.org/detectionstrategies/DET0416#AN1169","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=3, 22","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"NSM:Flow","channel":"ftp.log, smb_files.log","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"ProcessImageFilter","description":"Limit to non-standard FTP clients or suspicious binaries (e.g., cmd, mshta)"},{"field":"DataFlowDirectionThreshold","description":"Ratio of outbound:inbound bytes; e.g., >90% outbound"},{"field":"FilenamePattern","description":"Suspicious file extensions or naming (e.g., .zip, .rar, random hash names)"}],"live":true,"detection_strategies":["DET0416"],"techniques":["T1071.002"]},{"id":"AN1170","stix_id":"x-mitre-analytic--170e84e2-fa22-4e8c-b2f3-3cafc0d96d7e","name":"Analytic 1170","description":"Detects usage of FTP, SCP, or TFTP by non-interactive shells or automation scripts transferring large data volumes to untrusted IPs.","url":"https://attack.mitre.org/detectionstrategies/DET0416#AN1170","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"},{"name":"NSM:Flow","channel":"ftp.log, conn.log","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"TransferSizeThreshold","description":"Bytes sent in FTP upload or SCP push"},{"field":"CommandLinePatternMatch","description":"e.g., scp -r /var/log/* or ftp upload scripts"}],"live":true,"detection_strategies":["DET0416"],"techniques":["T1071.002"]},{"id":"AN1171","stix_id":"x-mitre-analytic--9e9efdc0-82d3-4046-a4db-e97454f708a6","name":"Analytic 1171","description":"Detects Automator, AppleScript, or Terminal executing curl, lftp, or TFTP for binary transfer to untrusted IPs or unusual ports.","url":"https://attack.mitre.org/detectionstrategies/DET0416#AN1171","platforms":["macOS"],"log_source_references":[{"name":"macos:osquery","channel":"socket_events","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"macos-osquery"},{"name":"macos:unifiedlog","channel":"log stream --predicate","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"FilePathAccessed","description":"e.g., ~/Documents, ~/Library/logs/"},{"field":"NetworkPortAnomaly","description":"Non-standard FTP/TFTP ports used (e.g., FTP over 443)"}],"live":true,"detection_strategies":["DET0416"],"techniques":["T1071.002"]},{"id":"AN1172","stix_id":"x-mitre-analytic--61e3802a-c95c-43c2-8749-139e0f750169","name":"Analytic 1172","description":"Detects file movement or outbound TFTP/FTP transfers from ESXi host initiated via shell commands or injected scripts, particularly from scratch partitions or /tmp.","url":"https://attack.mitre.org/detectionstrategies/DET0416#AN1172","platforms":["ESXi"],"log_source_references":[{"name":"esxi:shell","channel":"/root/.ash_history","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"esxi-shell"},{"name":"NSM:Flow","channel":"mirror/SPAN port","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"TransferTargetDomainOrIP","description":"Public IPs or domains not belonging to known ESXi mgmt infra"},{"field":"SourceDirectoryFilter","description":"Monitor transfers from /tmp/, /etc/, /vmfs/volumes/"}],"live":true,"detection_strategies":["DET0416"],"techniques":["T1071.002"]},{"id":"AN1173","stix_id":"x-mitre-analytic--9c5ef78d-2e02-4201-ba38-ec858e8b6a6f","name":"Analytic 1173","description":"Detects internal hosts generating large outbound FTP/TFTP/SMB sessions to external IPs, or file transfers using non-standard ports and application mismatches (e.g., FTP over port 80).","url":"https://attack.mitre.org/detectionstrategies/DET0416#AN1173","platforms":["Network Devices"],"log_source_references":[{"name":"NSM:Flow","channel":"ftp.log, conn.log, smb_files.log","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"AppLayerProtocolMatch","description":"e.g., FTP/SMB observed over uncommon ports"},{"field":"OutboundDataRateThreshold","description":"Bytes transferred outside trusted subnets >100MB"}],"live":true,"detection_strategies":["DET0416"],"techniques":["T1071.002"]}],"live":true,"version":"1.0","techniques":["T1071.002"]}],"sigma_rules":[],"kev_cves":[{"cveID":"CVE-2023-40044","state":"mapped","mapping_types":["primary_impact"]}],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}