{"id":"T1071","name":"Application Layer Protocol","url":"https://attack.mitre.org/techniques/T1071","tactics":["command-and-control"],"platforms":["Linux","macOS","Windows","Network Devices","ESXi"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0444","stix_id":"x-mitre-detection-strategy--155cab5b-c70b-4cfb-ba52-f62a21836b19","name":"Detection of Command and Control Over Application Layer Protocols","url":"https://attack.mitre.org/detectionstrategies/DET0444","analytics":[{"id":"AN1225","stix_id":"x-mitre-analytic--908aa2d1-f1c0-456b-9c9f-b984b309e51c","name":"Analytic 1225","description":"Detects suspicious usage of common application-layer protocols (e.g., HTTP, HTTPS, DNS, SMB) by abnormal processes, with high outbound byte counts or irregular ports, possibly indicating command and control or data exfiltration.","url":"https://attack.mitre.org/detectionstrategies/DET0444#AN1225","platforms":["Windows"],"log_source_references":[{"name":"NSM:Flow","channel":"http, dns, smb, ssl logs","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"nsm-flow"},{"name":"WinEventLog:Sysmon","channel":"EventCode=3, 22","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"ProtocolList","description":"Limit detection to app-layer protocols of interest: HTTP, DNS, SSL, SMB, RDP"},{"field":"DataVolumeThreshold","description":"Detects asymmetric communication volume (e.g., >90% outbound)"},{"field":"UnusualProcessList","description":"Track processes not normally associated with network activity"}],"live":true,"detection_strategies":["DET0444"],"techniques":["T1071"]},{"id":"AN1226","stix_id":"x-mitre-analytic--989a524f-cf9a-4fcc-a21f-ac5aac46f0ed","name":"Analytic 1226","description":"Detects suspicious curl, wget, or custom socket traffic that leverages DNS, HTTPS, or IRC-style protocols with unbalanced traffic or beacon-like intervals.","url":"https://attack.mitre.org/detectionstrategies/DET0444#AN1226","platforms":["Linux"],"log_source_references":[{"name":"NSM:Flow","channel":"dns, ssl, conn","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"nsm-flow"},{"name":"auditd:SYSCALL","channel":"execve","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"}],"mutable_elements":[{"field":"KnownPortsToMonitor","description":"Uncommon ports for HTTPS, IRC, DNS (e.g., 8443, 5353)"},{"field":"BeaconTimingThreshold","description":"Detect intervals of outbound traffic within fixed timeframes"}],"live":true,"detection_strategies":["DET0444"],"techniques":["T1071"]},{"id":"AN1227","stix_id":"x-mitre-analytic--c2b959ca-75f4-4291-9812-0b065e7bb395","name":"Analytic 1227","description":"Detects applications using abnormal protocols or high volume traffic not previously associated with the process image, such as Automator or AppleScript invoking curl or python sockets.","url":"https://attack.mitre.org/detectionstrategies/DET0444#AN1227","platforms":["macOS"],"log_source_references":[{"name":"macos:osquery","channel":"socket_events","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"macos-osquery"},{"name":"macos:unifiedlog","channel":"log stream","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"SocketParentProcessMatch","description":"Non-browser processes opening sockets to external IPs"},{"field":"DataFlowImbalanceRatio","description":"High outbound/inbound ratio indicating C2 beacon"}],"live":true,"detection_strategies":["DET0444"],"techniques":["T1071"]},{"id":"AN1228","stix_id":"x-mitre-analytic--c5117811-b262-4920-90d9-001d25b6305b","name":"Analytic 1228","description":"Detects application-layer tunneling or unauthorized app protocols like DNS-over-HTTPS, embedded C2 in TLS/HTTP headers, or misused SMB traffic crossing VLANs.","url":"https://attack.mitre.org/detectionstrategies/DET0444#AN1228","platforms":["Network Devices"],"log_source_references":[{"name":"NSM:Flow","channel":"conn.log, http.log, dns.log, ssl.log","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"AppProtocolAbusePattern","description":"Detects DNS tunneling, encrypted HTTP C2, or malformed headers"},{"field":"NorthSouthEgressFilter","description":"Monitor internal hosts talking externally using internal protocols (e.g., SMB)"}],"live":true,"detection_strategies":["DET0444"],"techniques":["T1071"]}],"live":true,"version":"1.0","techniques":["T1071"]}],"sigma_rules":[{"id":"03552375-cc2c-4883-bbe4-7958d5a980be","title":"HackTool - SILENTTRINITY Stager Execution","author":"Aleksey Potapov, oscd.community","status":"test","level":"high","date":"2019-10-22","modified":"2023-02-13","description":"Detects SILENTTRINITY stager use via PE metadata","references":["https://github.com/byt3bl33d3r/SILENTTRINITY"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.command-and-control","attack.t1071"],"path":"rules/windows/process_creation/proc_creation_win_hktl_silenttrinity_stager.yml","techniques":["T1071"],"cves":[]},{"id":"0ea52357-cd59-4340-9981-c46c7e900428","title":"Potentially Suspicious Rundll32.EXE Execution of UDL File","author":"@kostastsale","status":"test","level":"medium","date":"2024-08-16","modified":null,"description":"Detects the execution of rundll32.exe with the oledb32.dll library to open a UDL file.\nThreat actors can abuse this technique as a phishing vector to capture authentication credentials or other sensitive data.\n","references":["https://trustedsec.com/blog/oops-i-udld-it-again"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.command-and-control","attack.stealth","attack.t1218.011","attack.t1071"],"path":"rules/windows/process_creation/proc_creation_win_rundll32_udl_exec.yml","techniques":["T1218.011","T1071"],"cves":[]},{"id":"3db10f25-2527-4b79-8d4b-471eb900ee29","title":"GALLIUM Artefacts - Builtin","author":"Tim Burrell","status":"test","level":"high","date":"2020-02-07","modified":"2023-01-02","description":"Detects artefacts associated with activity group GALLIUM - Microsoft Threat Intelligence Center indicators released in December 2019.","references":["https://www.microsoft.com/security/blog/2019/12/12/gallium-targeting-global-telecom/","https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-R2-and-2012/dn800669(v=ws.11)"],"logsource":{"product":"windows","service":"dns-server-analytic"},"tags":["attack.credential-access","attack.command-and-control","attack.t1071","detection.emerging-threats"],"path":"rules-emerging-threats/2020/TA/GALLIUM/win_dns_analytic_apt_gallium.yml","techniques":["T1071"],"cves":[]},{"id":"440a56bf-7873-4439-940a-1c8a671073c2","title":"GALLIUM IOCs","author":"Tim Burrell","status":"test","level":"high","date":"2020-02-07","modified":"2024-11-23","description":"Detects artifacts associated with GALLIUM cyber espionage group as reported by Microsoft Threat Intelligence Center in the December 2019 report.","references":["https://www.microsoft.com/security/blog/2019/12/12/gallium-targeting-global-telecom/","https://github.com/Azure/Azure-Sentinel/blob/a02ce85c96f162de6f8cc06f07a53b6525f0ff7f/Solutions/Legacy%20IOC%20based%20Threat%20Protection/Analytic%20Rules/GalliumIOCs.yaml"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.credential-access","attack.command-and-control","attack.t1212","attack.t1071","attack.g0093","detection.emerging-threats"],"path":"rules-emerging-threats/2020/TA/GALLIUM/proc_creation_win_apt_gallium_iocs.yml","techniques":["T1212","T1071"],"cves":[]},{"id":"5bac7a56-da88-4c27-922e-c81e113b20cb","title":"Github Self-Hosted Runner Execution","author":"Daniel Koifman (KoifSec)","status":"test","level":"medium","date":"2025-11-29","modified":null,"description":"Detects GitHub self-hosted runners executing workflows on local infrastructure that could be abused for persistence and code execution.\nShai-Hulud is an npm supply chain worm targeting CI/CD environments.\nIt installs runners on compromised systems to maintain access after credential theft, leveraging their access to secrets and internal networks.\n","references":["https://about.gitlab.com/blog/gitlab-discovers-widespread-npm-supply-chain-attack/","https://securitylabs.datadoghq.com/articles/shai-hulud-2.0-npm-worm/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.command-and-control","attack.t1102.002","attack.t1071"],"path":"rules/windows/process_creation/proc_creation_win_github_self_hosted_runner.yml","techniques":["T1102.002","T1071"],"cves":[]},{"id":"75c505b1-711d-4f68-a357-8c3fe37dbf2d","title":"HackTool - SILENTTRINITY Stager DLL Load","author":"Aleksey Potapov, oscd.community","status":"test","level":"high","date":"2019-10-22","modified":"2023-02-17","description":"Detects SILENTTRINITY stager dll loading activity","references":["https://github.com/byt3bl33d3r/SILENTTRINITY"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.command-and-control","attack.t1071"],"path":"rules/windows/image_load/image_load_hktl_silenttrinity_stager.yml","techniques":["T1071"],"cves":[]},{"id":"e0cfaecd-602d-41af-988d-f6ccebb2af26","title":"Suspicious Installer Package Child Process","author":"Sohan G (D4rkCiph3r)","status":"test","level":"medium","date":"2023-02-18","modified":null,"description":"Detects the execution of suspicious child processes from macOS installer package parent process. This includes osascript, JXA, curl and wget amongst other interpreters","references":["https://redcanary.com/blog/clipping-silver-sparrows-wings/","https://github.com/elastic/detection-rules/blob/4312d8c9583be524578a14fe6295c3370b9a9307/rules/macos/execution_installer_package_spawned_network_event.toml"],"logsource":{"product":"macos","category":"process_creation"},"tags":["attack.t1059","attack.t1059.007","attack.t1071","attack.t1071.001","attack.execution","attack.command-and-control"],"path":"rules/macos/process_creation/proc_creation_macos_installer_susp_child_process.yml","techniques":["T1059","T1059.007","T1071","T1071.001"],"cves":[]}],"kev_cves":[{"cveID":"CVE-2021-45382","state":"mapped","mapping_types":["secondary_impact"]}],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}