kevmap

TechniquesT1102 › T1102.002

T1102.002 Bidirectional Communication

command and control — ESXi, Linux, macOS, Windows · attack.mitre.org · JSON

1
MITRE detection strategy
3
analytics
4
Sigma rules tagged attack.t1102.002
0
KEV CVEs mapped here
<p>Adversaries may use an existing, legitimate external Web service as a means for sending commands to and receiving output from a compromised system over the Web service channel. Compromised systems may leverage popular websites and social media to host command and control (C2) instructions. Those infected systems can then send the output from those commands back over that Web service channel. The return traffic may occur in a variety of ways, depending on the Web service being utilized. For example, the return traffic may take the form of the compromised system posting a comment on a forum, issuing a pull request to development project, updating a document hosted on a Web service, or by sending a Tweet.</p><p>Popular websites and social media acting as a mechanism for C2 may give a significant amount of cover due to the likelihood that hosts within a network are already communicating with them prior to a compromise. Using common services, such as those offered by Google or Twitter, makes it easier for adversaries to hide in expected noise. Web service providers commonly use SSL/TLS encryption, giving adversaries an added level of protection.</p>

KEV CVEs mapped to this technique · CTID Mappings Explorer

None. No KEV entry in the public mapping names this technique. Given that 74.7% of KEV has no mapping at all, this says more about the mapping than about the technique.

Detection strategy · ATT&CK Enterprise v19.2

Sigma rules · SigmaHQ da9bb07d64, tag attack.t1102.002

Author: Daniel Koifman (KoifSec) · 2025-11-29 · logsource: product=windows category=process_creation · 5bac7a56-da88-4c27-922e-c81e113b20cb
Detects GitHub self-hosted runners executing workflows on local infrastructure that could be abused for persistence and code execution. Shai-Hulud is an npm supply chain worm targeting CI/CD environments. It installs runners on compromised systems to maintain access after credential theft, leveraging their access to secrets and internal networks.
Techniques: T1102.002T1071
Author: Isaac Dunham · 2024-11-07 · logsource: product=windows category=network_connection · 8cb4d14e-776e-43c2-8fb9-91e7fcea32b4
Detects connections with Azure Front Door (known legitimate service that can be leveraged for C2) that fall outside of known benign behavioral baseline (not using common apps or common azurefd.net endpoints)
Techniques: T1102.002T1090.004
Author: Florian Roth (Nextron Systems) · 2018-06-05 (modified 2023-05-18) · logsource: category=proxy · b494b165-6634-483d-8c47-2026a6c52372
Detects suspicious requests to Telegram API without the usual Telegram User-Agent
Techniques: T1071.001T1102.002
Author: Florian Roth (Nextron Systems) · 2018-06-05 (modified 2022-10-09) · logsource: category=dns · c64c5175-5189-431b-a55e-6d9882158251
Detects suspicious DNS queries to api.telegram.org used by Telegram Bots of any kind
Techniques: T1102.002

Rules tagged at the parent level (attack.t1102) 13

These target the parent technique, not this sub-technique specifically. Listed for completeness, not counted as coverage.

Author: Florian Roth (Nextron Systems) · 2022-07-16 (modified 2025-07-30) · logsource: product=windows category=network_connection · 18249279-932f-45e2-b37a-8925f2597670
Detects an executable initiating a network connection to "ngrok" domains. Attackers were seen using this "ngrok" in order to store their second stage payloads and malware. While communication with such domains can be legitimate, often times is a sign of either data exfiltration by malicious actors or additional download.
Techniques: T1567T1572T1102
Author: Florian Roth (Nextron Systems) · 2022-11-03 · logsource: product=linux category=network_connection · 19bf6fdb-7721-4f3d-867f-53467f6a5db6
Detects an executable accessing an ngrok tunneling endpoint, which could be a sign of forbidden exfiltration of data exfiltration by malicious actors
Author: Florian Roth (Nextron Systems) · 2022-11-03 (modified 2024-02-02) · logsource: product=windows category=network_connection · 1d08ac94-400d-4469-a82f-daee9a908849
Detects an executable initiating a network connection to "ngrok" tunneling domains. Attackers were seen using this "ngrok" in order to store their second stage payloads and malware. While communication with such domains can be legitimate, often times is a sign of either data exfiltration by malicious actors or additional download.
Author: Sorina Ionescu, X__Junior (Nextron Systems) · 2022-08-17 (modified 2026-03-29) · logsource: product=windows category=network_connection · 297ae038-edc2-4b2e-bb3e-7c5fc94dd5c7
Detects an executable, which is not an internet browser or known application, initiating network connections to legit popular websites, which were seen to be used as dead drop resolvers in previous attacks. In this context attackers leverage known websites such as "facebook", "youtube", etc. In order to pass through undetected.
Techniques: T1102T1102.001
Author: Andreas Braathen (mnemonic.io) · 2024-06-17 · logsource: product=windows category=network_connection · 3ab65069-d82a-4d44-a759-466661a082d1
Detects an executable initiating a network connection to "LocaltoNet" tunneling sub-domains. LocaltoNet is a reverse proxy that enables localhost services to be exposed to the Internet. Attackers have been seen to use this service for command-and-control activities to bypass MFA and perimeter controls.
Techniques: T1572T1090T1102
Author: Nasreddine Bencherchali (Nextron Systems) · 2024-06-24 (modified 2024-07-16) · logsource: product=windows category=network_connection · 5c80b618-0dbb-46e6-acbb-03d90bcb6d83
Detects an initiated network connection by a non browser process on the system to "azurewebsites.net". The latter was often used by threat actors as a malware hosting and exfiltration site.
Techniques: T1102T1102.001
Author: Nasreddine Bencherchali (Nextron Systems) · 2023-05-17 (modified 2023-12-21) · logsource: product=windows category=process_creation · 7050bba1-1aed-454e-8f73-3f46f09ce56a
Detects execution of the "cloudflared" tool with the tunnel "cleanup" flag in order to cleanup tunnel connections.
Techniques: T1102T1090T1572
Author: Gavin Knapp · 2023-05-01 (modified 2025-02-22) · logsource: product=windows category=network_connection · 7e9cf7b6-e827-11ed-a05b-0242ac120003
Detects a non-browser process interacting with the Google API which could indicate the use of a covert C2 such as Google Sheet C2 (GC2-sheet)
Techniques: T1102
Author: Gavin Knapp · 2023-05-03 · logsource: product=windows category=network_connection · 7e9cf7b6-e827-11ed-a05b-15959c120003
Detects a non-browser process communicating with the Notion API. This could indicate potential use of a covert C2 channel such as "OffensiveNotion C2"
Techniques: T1102
Author: Janantha Marasinghe, Nasreddine Bencherchali (Nextron Systems) · 2023-05-17 (modified 2023-12-20) · logsource: product=windows category=process_creation · 9a019ffc-3580-4c9d-8d87-079f7e8d3fd4
Detects execution of the "cloudflared" tool to connect back to a tunnel. This was seen used by threat actors to maintain persistence and remote access to compromised networks.
Techniques: T1102T1090T1572
Author: Nasreddine Bencherchali (Nextron Systems) · 2023-05-19 · logsource: product=windows category=network_connection · c3dbbc9f-ef1d-470a-a90a-d343448d5875
Detects an a non-browser process interacting with the Telegram API which could indicate use of a covert C2
Techniques: T1102T1567T1105
Author: Andreas Braathen (mnemonic.io) · 2024-06-17 · logsource: product=linux category=network_connection · c4568f5d-131f-4e78-83d4-45b2da0ec4f1
Detects an executable initiating a network connection to "LocaltoNet" tunneling sub-domains. LocaltoNet is a reverse proxy that enables localhost services to be exposed to the Internet. Attackers have been seen to use this service for command-and-control activities to bypass MFA and perimeter controls.
Techniques: T1572T1090T1102
Author: Florian Roth (Nextron Systems) · 2023-01-18 (modified 2023-08-29) · logsource: product=windows category=process_creation · cea2b7ea-792b-405f-95a1-b903ea06458f
Detects suspicious child processes of the "Manage Engine ServiceDesk Plus" Java web service
Techniques: T1102