{"id":"T1205.002","name":"Socket Filters","url":"https://attack.mitre.org/techniques/T1205/002","tactics":["stealth","persistence","command-and-control"],"platforms":["Linux","macOS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0162","stix_id":"x-mitre-detection-strategy--b4cdf164-9cb7-4cad-bdc3-81b5574f364a","name":"Socket-filter trigger → on-host raw-socket activity → reverse connection (T1205.002)","url":"https://attack.mitre.org/detectionstrategies/DET0162","analytics":[{"id":"AN0462","stix_id":"x-mitre-analytic--98d733c2-370b-4cd0-8ec6-226a1ca19604","name":"Analytic 0462","description":"Adversary installs/uses packet-capture or raw-socket capability (WinPcap/Npcap, wpcap/packet DLLs or raw socket attach) and sets a filter. A crafted inbound packet is observed; within a short window the host process that loaded capture libraries initiates an outbound connection (e.g., reverse shell) to the packet origin.","url":"https://attack.mitre.org/detectionstrategies/DET0162#AN0462","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:System","channel":"EventCode=7045","data_component":"DC0060","data_component_name":"Service Creation","log_source_slug":"wineventlog-system"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=3, 22","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=6","data_component":"DC0079","data_component_name":"Driver Load","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=7","data_component":"DC0016","data_component_name":"Module Load","log_source_slug":"wineventlog-sysmon"},{"name":"NSM:Flow","channel":"Single, low-volume inbound packet (REJ/S0/OTH or uncommon dport/protocol) from src_ip followed by outbound SF connection to src_ip.","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"TimeWindow","description":"Seconds to correlate inbound trigger → process library load/driver start → outbound connect (default 120s)."},{"field":"CaptureLibIndicators","description":"DLL/driver names to match (wpcap.dll, packet.dll, npcap.sys, npf.sys) – extend for EDR drivers in your fleet."},{"field":"AllowedInstallers","description":"Signed/expected processes allowed to install/start Npcap (software distribution tools)."},{"field":"ReversePorts","description":"Likely egress ports to watch after trigger (4444, 53, 80/443, 8080, high ephemeral)."}],"live":true,"detection_strategies":["DET0162"],"techniques":["T1205.002"]},{"id":"AN0463","stix_id":"x-mitre-analytic--c19f8f89-76f9-4345-8bb6-a065fba50bff","name":"Analytic 0463","description":"Process creates a raw/packet socket and attaches a (e)BPF filter (setsockopt SO_ATTACH_FILTER/ATTACH_BPF or bpf(BPF_PROG_LOAD)). Immediately after a matching inbound packet, the same process binds/connects outward to a remote host (reverse shell or beacon).","url":"https://attack.mitre.org/detectionstrategies/DET0162#AN0463","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"socket(AF_PACKET|AF_INET, SOCK_RAW, *), setsockopt(… SO_ATTACH_FILTER|SO_ATTACH_BPF …), bpf(cmd=BPF_PROG_LOAD), open/openat path=\"/dev/bpf*\" (BSD/macOS-like) or setcap cap_net_raw.","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"},{"name":"linux:osquery","channel":"family=AF_PACKET or protocol raw; process name not in allowlist.","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"linux-osquery"},{"name":"NSM:Flow","channel":"Rare inbound packet characteristics (ICMP/UDP/TCP to uncommon port) from src_ip followed ≤TimeWindow by outbound SF from same host to src_ip.","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"UserContext","description":"Flag raw-socket activity outside privileged daemons (root-only by default)."},{"field":"MinPayloadEntropy","description":"If using packet content (Zeek), treat high-entropy single-packet triggers as suspicious."},{"field":"AFPacketAllowList","description":"System services allowed to open AF_PACKET (dhclient, keepalived, LLDP, monitoring agents)."}],"live":true,"detection_strategies":["DET0162"],"techniques":["T1205.002"]},{"id":"AN0464","stix_id":"x-mitre-analytic--e6d04b50-7bdc-480e-9bda-291db9b270f6","name":"Analytic 0464","description":"Process opens /dev/bpf* (libpcap) or loads NetworkExtension filter, then after a crafted inbound packet the same process initiates an outbound connection to the trigger origin.","url":"https://attack.mitre.org/detectionstrategies/DET0162#AN0464","platforms":["macOS"],"log_source_references":[{"name":"OpenBSM:AuditTrail","channel":"open/openat of /dev/bpf*; ioctl BIOCSETF-like operations.","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"openbsm-audittrail"},{"name":"macos:unifiedlog","channel":"First outbound connection from the same PID/user shortly after an inbound trigger.","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"macos-unifiedlog"},{"name":"NSM:Flow","channel":"Inbound one-off packet to uncommon port → outbound SF to same src_ip within TimeWindow.","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"BPFDevicePath","description":"Alternate BPF device paths if customized (default /dev/bpf*)."},{"field":"DeveloperMode","description":"Relax thresholds on known developer tooling hosts (Xcode, instrumenting tools)."}],"live":true,"detection_strategies":["DET0162"],"techniques":["T1205.002"]}],"live":true,"version":"1.0","techniques":["T1205.002"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}