{"id":"T1102.002","name":"Bidirectional Communication","url":"https://attack.mitre.org/techniques/T1102/002","tactics":["command-and-control"],"platforms":["ESXi","Linux","macOS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0035","stix_id":"x-mitre-detection-strategy--dcf2474e-0774-40da-b7e6-f4b60d0ea62f","name":"Detect Bidirectional Web Service C2 Channels via Process & Network Correlation","url":"https://attack.mitre.org/detectionstrategies/DET0035","analytics":[{"id":"AN0100","stix_id":"x-mitre-analytic--27bd3e33-9a61-4dfb-9fba-205a6c880264","name":"Analytic 0100","description":"Suspicious processes initiating encrypted HTTPS connections to common web service domains, followed by abnormal data upload behavior or automated posting behavior indicative of C2 bidirectional traffic.","url":"https://attack.mitre.org/detectionstrategies/DET0035#AN0100","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=3, 22","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"etw:Microsoft-Windows-WinINet","channel":"HTTPS Inspection","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"etw-microsoft-windows-wininet"}],"mutable_elements":[{"field":"TimeWindow","description":"Timeframe for evaluating multiple network connections tied to the same process"},{"field":"DomainPattern","description":"Regex or string patterns used to identify common Web service infrastructure (e.g., *.googleapis.com)"},{"field":"PayloadSizeThreshold","description":"Minimum data upload size before flagging anomaly"},{"field":"ProcessNameExclusionList","description":"Known benign updaters or service processes to reduce false positives"}],"live":true,"detection_strategies":["DET0035"],"techniques":["T1102.002"]},{"id":"AN0101","stix_id":"x-mitre-analytic--1edab644-3ec0-4c5d-bc26-18744fbc7a6e","name":"Analytic 0101","description":"Non-interactive system processes making encrypted HTTPS connections to well-known web services followed by high outbound traffic volume or scripted upload patterns.","url":"https://attack.mitre.org/detectionstrategies/DET0035#AN0101","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"},{"name":"NSM:Flow","channel":"conn.log","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"nsm-flow"},{"name":"NSM:Flow","channel":"ssl.log","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"UploadDirectionality","description":"Bias detection toward sessions with larger upload vs download volume"},{"field":"HostnameRegexList","description":"List of known public Web services used for dead drops or C2 (e.g., GitHub, Twitter)"},{"field":"ScriptParentName","description":"Shell interpreter or automated job parent used for filtering (e.g., /usr/bin/python)"}],"live":true,"detection_strategies":["DET0035"],"techniques":["T1102.002"]},{"id":"AN0102","stix_id":"x-mitre-analytic--5935bda3-8d4d-44b4-aca4-8b40cf45f686","name":"Analytic 0102","description":"Scripting engines (e.g., osascript, Python) initiating HTTPS requests to social media or content-sharing platforms, paired with automated response handling indicative of two-way communication.","url":"https://attack.mitre.org/detectionstrategies/DET0035#AN0102","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"log stream --info --predicate 'subsystem == \"com.apple.cfprefsd\"'","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"},{"name":"NSM:Connections","channel":"web domain alerts","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"nsm-connections"}],"mutable_elements":[{"field":"ScriptEngineList","description":"Scripting interpreters to monitor for unusual HTTP traffic (e.g., osascript, ruby, bash)"},{"field":"SocialMediaDomainPatterns","description":"Patterns or domains used for C2 dead drops and responses (e.g., pastebin.com, twitter.com)"},{"field":"BurstConnectionRate","description":"Threshold for number of short-lived HTTPS connections in a short window"}],"live":true,"detection_strategies":["DET0035"],"techniques":["T1102.002"]}],"live":true,"version":"1.0","techniques":["T1102.002"]}],"sigma_rules":[{"id":"5bac7a56-da88-4c27-922e-c81e113b20cb","title":"Github Self-Hosted Runner Execution","author":"Daniel Koifman (KoifSec)","status":"test","level":"medium","date":"2025-11-29","modified":null,"description":"Detects GitHub self-hosted runners executing workflows on local infrastructure that could be abused for persistence and code execution.\nShai-Hulud is an npm supply chain worm targeting CI/CD environments.\nIt installs runners on compromised systems to maintain access after credential theft, leveraging their access to secrets and internal networks.\n","references":["https://about.gitlab.com/blog/gitlab-discovers-widespread-npm-supply-chain-attack/","https://securitylabs.datadoghq.com/articles/shai-hulud-2.0-npm-worm/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.command-and-control","attack.t1102.002","attack.t1071"],"path":"rules/windows/process_creation/proc_creation_win_github_self_hosted_runner.yml","techniques":["T1102.002","T1071"],"cves":[]},{"id":"8cb4d14e-776e-43c2-8fb9-91e7fcea32b4","title":"Potentially Suspicious Azure Front Door Connection","author":"Isaac Dunham","status":"test","level":"medium","date":"2024-11-07","modified":null,"description":"Detects connections with Azure Front Door (known legitimate service that can be leveraged for C2)\nthat fall outside of known benign behavioral baseline (not using common apps or common azurefd.net endpoints)\n","references":["https://lots-project.com/site/2a2e617a75726566642e6e6574","https://medium.com/r3d-buck3t/red-teaming-in-cloud-leverage-azure-frontdoor-cdn-for-c2-redirectors-79dd9ca98178","https://www.fortalicesolutions.com/posts/hiding-behind-the-front-door-with-azure-domain-fronting"],"logsource":{"product":"windows","category":"network_connection"},"tags":["attack.command-and-control","attack.t1102.002","attack.t1090.004","detection.threat-hunting"],"path":"rules-threat-hunting/windows/network_connection/net_connection_win_susp_azurefd_connection.yml","techniques":["T1102.002","T1090.004"],"cves":[]},{"id":"b494b165-6634-483d-8c47-2026a6c52372","title":"Telegram API Access","author":"Florian Roth (Nextron Systems)","status":"test","level":"medium","date":"2018-06-05","modified":"2023-05-18","description":"Detects suspicious requests to Telegram API without the usual Telegram User-Agent","references":["https://researchcenter.paloaltonetworks.com/2018/03/unit42-telerat-another-android-trojan-leveraging-telegrams-bot-api-to-target-iranian-users/","https://blog.malwarebytes.com/threat-analysis/2016/11/telecrypt-the-ransomware-abusing-telegram-api-defeated/","https://www.welivesecurity.com/2016/12/13/rise-telebots-analyzing-disruptive-killdisk-attacks/"],"logsource":{"category":"proxy"},"tags":["attack.command-and-control","attack.t1071.001","attack.t1102.002"],"path":"rules/web/proxy_generic/proxy_telegram_api.yml","techniques":["T1071.001","T1102.002"],"cves":[]},{"id":"c64c5175-5189-431b-a55e-6d9882158251","title":"Telegram Bot API Request","author":"Florian Roth (Nextron Systems)","status":"test","level":"medium","date":"2018-06-05","modified":"2022-10-09","description":"Detects suspicious DNS queries to api.telegram.org used by Telegram Bots of any kind","references":["https://core.telegram.org/bots/faq","https://researchcenter.paloaltonetworks.com/2018/03/unit42-telerat-another-android-trojan-leveraging-telegrams-bot-api-to-target-iranian-users/","https://blog.malwarebytes.com/threat-analysis/2016/11/telecrypt-the-ransomware-abusing-telegram-api-defeated/","https://www.welivesecurity.com/2016/12/13/rise-telebots-analyzing-disruptive-killdisk-attacks/"],"logsource":{"category":"dns"},"tags":["attack.command-and-control","attack.t1102.002"],"path":"rules/network/dns/net_dns_susp_telegram_api.yml","techniques":["T1102.002"],"cves":[]}],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}