{"id":"T1095","name":"Non-Application Layer Protocol","url":"https://attack.mitre.org/techniques/T1095","tactics":["command-and-control"],"platforms":["ESXi","Linux","macOS","Network Devices","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0457","stix_id":"x-mitre-detection-strategy--2cb544af-ef54-4376-9608-b399ad67d3d6","name":"Detection of Non-Application Layer Protocols for C2","url":"https://attack.mitre.org/detectionstrategies/DET0457","analytics":[{"id":"AN1254","stix_id":"x-mitre-analytic--4412fb07-9a44-49de-80af-8746b0be3865","name":"Analytic 1254","description":"Anomalous use of ICMP or UDP by non-network service processes for data exfiltration or remote control, especially if traffic bypasses proxy infrastructure or shows unusual flow patterns.","url":"https://attack.mitre.org/detectionstrategies/DET0457#AN1254","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=3, 22","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"wineventlog-sysmon"},{"name":"NSM:Flow","channel":"ICMP/UDP traffic (Wireshark, Suricata, Zeek)","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"ProcessContextAllowList","description":"Processes normally allowed to use ICMP/UDP (e.g., ping.exe, DNS resolver)."},{"field":"ByteTransferAnomalyThreshold","description":"Suspicion if client sends much more data than it receives (e.g., >90%)."},{"field":"ProtocolUsageBaseline","description":"Baseline which protocols are normal per host or segment (ICMP, UDP, etc.)."}],"live":true,"detection_strategies":["DET0457"],"techniques":["T1095"]},{"id":"AN1255","stix_id":"x-mitre-analytic--7d0a3871-8cee-47bd-8829-637e132c98f7","name":"Analytic 1255","description":"ICMP or raw socket traffic generated by user-mode processes like bash, Python, or nc, typically using `ping`, `hping3`, or crafted packets via libpcap or scapy.","url":"https://attack.mitre.org/detectionstrategies/DET0457#AN1255","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"sendto/connect","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"auditd-syscall"},{"name":"NSM:Flow","channel":"icmp.log, weird.log","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"RawSocketExecutionPath","description":"Uncommon programs using raw sockets (e.g., netcat, Python, nmap)."},{"field":"TimeWindow","description":"Tunable window for correlating execution with network events (e.g., 2m)."}],"live":true,"detection_strategies":["DET0457"],"techniques":["T1095"]},{"id":"AN1256","stix_id":"x-mitre-analytic--4742e058-a301-47e1-b594-8daa8eabfc79","name":"Analytic 1256","description":"Unsigned binaries or interpreted scripts initiating non-standard protocols (ICMP, UDP, SOCKS) outside of baseline network behavior.","url":"https://attack.mitre.org/detectionstrategies/DET0457#AN1256","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"com.apple.network","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"macos-unifiedlog"},{"name":"NSM:Flow","channel":"ICMP/UDP monitoring (tcpdump, Wireshark, Zeek)","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"UnsignedBinaryNetworkUsage","description":"Detection threshold for unsigned or transient binaries making ICMP/UDP calls."}],"live":true,"detection_strategies":["DET0457"],"techniques":["T1095"]},{"id":"AN1257","stix_id":"x-mitre-analytic--cae917e6-7542-41d0-8b03-ad2b7ab1eb01","name":"Analytic 1257","description":"VMCI (Virtual Machine Communication Interface) traffic between guest and host, or between VMs, originating from non-management tools or unauthorized binaries.","url":"https://attack.mitre.org/detectionstrategies/DET0457#AN1257","platforms":["ESXi"],"log_source_references":[{"name":"esxi:vmkernel","channel":"VMCI syslog entries","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"esxi-vmkernel"}],"mutable_elements":[{"field":"VMCIBackdoorProcess","description":"Monitor for non-vSphere or VMware-native processes using VMCI."},{"field":"GuestToHostCommPattern","description":"Baseline pattern of guest-to-host traffic vs anomaly (unexpected port, volume)."}],"live":true,"detection_strategies":["DET0457"],"techniques":["T1095"]},{"id":"AN1258","stix_id":"x-mitre-analytic--688ed638-d3ba-47dc-baa7-16b16a9fe9c8","name":"Analytic 1258","description":"Non-standard port/protocol pairings or low-entropy ICMP traffic resembling tunneling patterns (e.g., fixed-size pings with delays).","url":"https://attack.mitre.org/detectionstrategies/DET0457#AN1258","platforms":["Network Devices"],"log_source_references":[{"name":"NSM:Firewall","channel":"ICMP/UDP protocol anomaly","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"nsm-firewall"},{"name":"NSM:Flow","channel":"conn.log, icmp.log","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"ProtocolEntropyThreshold","description":"ICMP/UDP packet content entropy filter to identify encoded payloads."},{"field":"SessionDurationThreshold","description":"Long ICMP/UDP sessions beyond expected limits (e.g., >5min)."}],"live":true,"detection_strategies":["DET0457"],"techniques":["T1095"]}],"live":true,"version":"1.0","techniques":["T1095"]}],"sigma_rules":[{"id":"c5b20776-639a-49bf-94c7-84f912b91c15","title":"Netcat The Powershell Version","author":"frack113","status":"test","level":"medium","date":"2021-07-21","modified":"2023-10-27","description":"Adversaries may use a non-application layer protocol for communication between host and C2 server or among infected hosts within a network","references":["https://nmap.org/ncat/","https://github.com/besimorhino/powercat","https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1095/T1095.md"],"logsource":{"product":"windows","category":"ps_classic_start"},"tags":["attack.command-and-control","attack.execution","attack.t1095","attack.t1059.001"],"path":"rules/windows/powershell/powershell_classic/posh_pc_powercat.yml","techniques":["T1095","T1059.001"],"cves":[]},{"id":"e31033fc-33f0-4020-9a16-faf9b31cbf08","title":"PUA - Netcat Suspicious Execution","author":"frack113, Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2021-07-21","modified":"2023-02-08","description":"Detects execution of Netcat. Adversaries may use a non-application layer protocol for communication between host and C2 server or among infected hosts within a network","references":["https://nmap.org/ncat/","https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1095/T1095.md","https://www.revshells.com/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.command-and-control","attack.t1095"],"path":"rules/windows/process_creation/proc_creation_win_pua_netcat.yml","techniques":["T1095"],"cves":[]},{"id":"ede05abc-2c9e-4624-9944-9ff17fdc0bf5","title":"Suspicious DNS Z Flag Bit Set","author":"@neu5ron, SOC Prime Team, Corelight","status":"test","level":"medium","date":"2021-05-04","modified":"2022-11-29","description":"The DNS Z flag is bit within the DNS protocol header that is, per the IETF design, meant to be used reserved (unused).\nAlthough recently it has been used in DNSSec, the value being set to anything other than 0 should be rare.\nOtherwise if it is set to non 0 and DNSSec is being used, then excluding the legitimate domains is low effort and high reward.\nDetermine if multiple of these files were accessed in a short period of time to further enhance the possibility of seeing if this was a one off or the possibility of larger sensitive file gathering.\nThis Sigma query is designed to accompany the Corelight Threat Hunting Guide, which can be found here: https://www3.corelight.com/corelights-introductory-guide-to-threat-hunting-with-zeek-bro-logs'\n","references":["https://twitter.com/neu5ron/status/1346245602502443009","https://tdm.socprime.com/tdm/info/eLbyj4JjI15v#sigma","https://tools.ietf.org/html/rfc2929#section-2.1","https://www.netresec.com/?page=Blog&month=2021-01&post=Finding-Targeted-SUNBURST-Victims-with-pDNS"],"logsource":{"product":"zeek","service":"dns"},"tags":["attack.t1095","attack.t1571","attack.command-and-control"],"path":"rules/network/zeek/zeek_dns_susp_zbit_flag.yml","techniques":["T1095","T1571"],"cves":[]}],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}