{"id":"T1496.002","name":"Bandwidth Hijacking","url":"https://attack.mitre.org/techniques/T1496/002","tactics":["impact"],"platforms":["Linux","Windows","macOS","IaaS","Containers"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0028","stix_id":"x-mitre-detection-strategy--c0a23061-c4f3-4003-9e81-e81d50b6d1e2","name":"Detect Excessive or Unauthorized Bandwidth Usage for Botnet, Proxyjacking, or Scanning Purposes","url":"https://attack.mitre.org/detectionstrategies/DET0028","analytics":[{"id":"AN0080","stix_id":"x-mitre-analytic--c699a4ee-83dd-48d8-94ae-658204066ae9","name":"Analytic 0080","description":"Processes invoking network-intensive child processes or uploading large data volumes, often from non-standard user or system contexts, with evidence of long-duration TCP/UDP sessions to unusual destinations.","url":"https://attack.mitre.org/detectionstrategies/DET0028#AN0080","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=3, 22","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"TimeWindow","description":"Bandwidth anomalies should be assessed over 5-15 min or hourly windows depending on environment size."},{"field":"DestinationCountry","description":"Some organizations whitelist traffic to countries based on geolocation."},{"field":"ProcessName","description":"Legitimate processes using high bandwidth (e.g., backup tools) must be excluded."}],"live":true,"detection_strategies":["DET0028"],"techniques":["T1496.002"]},{"id":"AN0081","stix_id":"x-mitre-analytic--10e9d109-0a17-41cd-9d0b-67c679bc94b7","name":"Analytic 0081","description":"User-initiated processes generating sustained outbound traffic over common or non-standard ports, often outside business hours, potentially linked to scanning or proxyjacking. Includes curl, wget, masscan, or proxy clients.","url":"https://attack.mitre.org/detectionstrategies/DET0028#AN0081","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve calls with high-frequency or known bandwidth-intensive tools","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"},{"name":"NSM:Flow","channel":"large outbound data flows or long-duration connections","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"ToolPattern","description":"Can be tuned for specific bandwidth abuse tools (e.g., proxychains, 3proxy)."},{"field":"TrafficRateThreshold","description":"Baseline deviation thresholds must be environment-specific."}],"live":true,"detection_strategies":["DET0028"],"techniques":["T1496.002"]},{"id":"AN0082","stix_id":"x-mitre-analytic--35a5d72b-6c69-498a-9118-14cd6c85a57a","name":"Analytic 0082","description":"Suspicious long-lived or high-throughput connections by non-Apple signed apps or processes not commonly associated with network uploads. Detect background processes using open sockets for data egress.","url":"https://attack.mitre.org/detectionstrategies/DET0028#AN0082","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"process + network metrics correlation for bandwidth saturation","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"exec or spawn calls to proxy tools or torrent clients","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"ProcessSignedStatus","description":"Non-signed or non-Apple signed binaries can raise confidence levels."},{"field":"DataRateThreshold","description":"Observed data rate per process over time (e.g., MB/s)."}],"live":true,"detection_strategies":["DET0028"],"techniques":["T1496.002"]},{"id":"AN0083","stix_id":"x-mitre-analytic--2fe9bf69-b1a8-4c60-8b20-c11054d31158","name":"Analytic 0083","description":"Containerized apps or sidecar containers generating excessive outbound traffic or being leveraged for proxy networks. Includes sudden increases in network interface stats, especially in dormant or low-util apps.","url":"https://attack.mitre.org/detectionstrategies/DET0028#AN0083","platforms":["Containers"],"log_source_references":[{"name":"containers:osquery","channel":"bandwidth-intensive command execution from within a container namespace","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"containers-osquery"},{"name":"docker:stats","channel":"unusual network TX/RX byte deltas","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"docker-stats"}],"mutable_elements":[{"field":"ContainerBaselineNetworkUsage","description":"Baseline per container must be defined by app purpose and normal traffic."},{"field":"ImageName","description":"Certain image names or registries may be prone to abuse (e.g., public image hosting mining or proxyware)."}],"live":true,"detection_strategies":["DET0028"],"techniques":["T1496.002"]},{"id":"AN0084","stix_id":"x-mitre-analytic--b0d018e2-0384-4e27-92ed-c9b181999fa9","name":"Analytic 0084","description":"Virtual instances or workloads generating sustained outbound data rates, often to TOR, VPN, or proxy endpoints. Often coincides with unusual IAM usage or deployed scripts (e.g., cron jobs using proxy clients).","url":"https://attack.mitre.org/detectionstrategies/DET0028#AN0084","platforms":["IaaS"],"log_source_references":[{"name":"AWS:CloudTrail","channel":"StartInstances","data_component":"DC0080","data_component_name":"Instance Start","log_source_slug":"aws-cloudtrail"},{"name":"AWS:VPCFlowLogs","channel":"egress > 90th percentile or frequent connection reuse","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"aws-vpcflowlogs"}],"mutable_elements":[{"field":"InstanceType","description":"High-throughput instance types are more likely to be targeted for hijacking."},{"field":"TrafficEgressThreshold","description":"Customize detection thresholds based on cloud provider quotas or billing alerts."}],"live":true,"detection_strategies":["DET0028"],"techniques":["T1496.002"]}],"live":true,"version":"1.0","techniques":["T1496.002"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}