{"id":"T1102.003","name":"One-Way Communication","url":"https://attack.mitre.org/techniques/T1102/003","tactics":["command-and-control"],"platforms":["Linux","macOS","Windows","ESXi"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0581","stix_id":"x-mitre-detection-strategy--e3718a7a-77b3-4790-99ba-aba7703815fd","name":"Detect One-Way Web Service Command Channels","url":"https://attack.mitre.org/detectionstrategies/DET0581","analytics":[{"id":"AN1599","stix_id":"x-mitre-analytic--8626f553-efed-4418-bbc6-b9fa83b0b315","name":"Analytic 1599","description":"Suspicious process initiating outbound connections to web services without corresponding response or return traffic, indicative of one-way command channels.","url":"https://attack.mitre.org/detectionstrategies/DET0581#AN1599","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=3, 22","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"wineventlog-sysmon"},{"name":"etw:Microsoft-Windows-WinINet","channel":"WinINet API telemetry","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"etw-microsoft-windows-wininet"}],"mutable_elements":[{"field":"DestinationDomain","description":"Can tune for popular web services (e.g., googleapis.com, github.com) based on threat actor tooling"},{"field":"TimeWindow","description":"May adjust temporal window to catch beaconing patterns (e.g., every 10-30 mins)"},{"field":"ProcessName","description":"Environment-specific tuning to exclude expected update or telemetry tools"}],"live":true,"detection_strategies":["DET0581"],"techniques":["T1102.003"]},{"id":"AN1600","stix_id":"x-mitre-analytic--e83afa89-0ec1-49e7-b351-eef67b085480","name":"Analytic 1600","description":"Curl, wget, or custom HTTP clients initiated by uncommon user accounts or cron jobs to popular web services, with no observed response parsing logic.","url":"https://attack.mitre.org/detectionstrategies/DET0581#AN1600","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"},{"name":"iptables:LOG","channel":"OUTBOUND","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"iptables-log"}],"mutable_elements":[{"field":"ParentProcess","description":"May tune to detect unknown parents like custom scripts or reverse shells"},{"field":"CommandLineArgs","description":"May adjust based on known curl/wget C2 behaviors"}],"live":true,"detection_strategies":["DET0581"],"techniques":["T1102.003"]},{"id":"AN1601","stix_id":"x-mitre-analytic--d49f06ba-7a81-440b-bc16-c583ba918a3d","name":"Analytic 1601","description":"Process using URLSession or similar API to fetch from web services without any response handling, indicative of one-way C2 channels.","url":"https://attack.mitre.org/detectionstrategies/DET0581#AN1601","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"process, network","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"macos-unifiedlog"},{"name":"macos:endpointsecurity","channel":"exec events","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-endpointsecurity"}],"mutable_elements":[{"field":"UserContext","description":"Flag unexpected outbound activity from non-admin or system users"},{"field":"EntropyScore","description":"Optional if script-based obfuscation is seen in web requests"}],"live":true,"detection_strategies":["DET0581"],"techniques":["T1102.003"]},{"id":"AN1602","stix_id":"x-mitre-analytic--5ce50294-f89c-4158-b5f2-7ca257a88837","name":"Analytic 1602","description":"ESXi shell or scheduled tasks initiating outbound HTTPS to known public services without inbound return or loggable response, used to fetch instructions.","url":"https://attack.mitre.org/detectionstrategies/DET0581#AN1602","platforms":["ESXi"],"log_source_references":[{"name":"esxi:hostd","channel":"CLI network calls","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"esxi-hostd"}],"mutable_elements":[{"field":"ScheduledTaskName","description":"Can tune for task names used to execute curl-based outbound requests"},{"field":"DestinationIP","description":"Scoped by environment to exclude known legitimate CDNs"}],"live":true,"detection_strategies":["DET0581"],"techniques":["T1102.003"]}],"live":true,"version":"1.0","techniques":["T1102.003"]}],"sigma_rules":[{"id":"2b1ee7e4-89b6-4739-b7bb-b811b6607e5e","title":"PwnDrp Access","author":"Florian Roth (Nextron Systems)","status":"test","level":"critical","date":"2020-04-15","modified":"2021-11-27","description":"Detects downloads from PwnDrp web servers developed for red team testing and most likely also used for criminal activity","references":["https://breakdev.org/pwndrop/"],"logsource":{"category":"proxy"},"tags":["attack.command-and-control","attack.t1071.001","attack.t1102.001","attack.t1102.003"],"path":"rules/web/proxy_generic/proxy_pwndrop.yml","techniques":["T1071.001","T1102.001","T1102.003"],"cves":[]},{"id":"5468045b-4fcc-4d1a-973c-c9c9578edacb","title":"Raw Paste Service Access","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2019-12-05","modified":"2023-01-19","description":"Detects direct access to raw pastes in different paste services often used by malware in their second stages to download malicious code in encrypted or encoded form","references":["https://www.virustotal.com/gui/domain/paste.ee/relations"],"logsource":{"category":"proxy"},"tags":["attack.command-and-control","attack.t1071.001","attack.t1102.001","attack.t1102.003"],"path":"rules/web/proxy_generic/proxy_raw_paste_service_access.yml","techniques":["T1071.001","T1102.001","T1102.003"],"cves":[]}],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}