Fallback Channels T1008
Tactic: Command & Control
Adversaries may use fallback or alternate communication channels if the primary channel is compromised or inaccessible in order to maintain reliable command and control and to avoid data transfer thresholds.
Events covered
4 catalog events are tagged with this technique by at least one rule.
| Provider | Event | Title |
|---|---|---|
| Sysmon | Event ID 11 | FileCreate |
| Sysmon | Event ID 13 | RegistryEvent (Value Set) |
| Sysmon | Event ID 22 | DNSEvent (DNS query) |
| ESF | exec | Process Execution |
Authoring guide
These 17 rules share fields, values, and exclusions.
Fields filtered most (31 distinct)
These fields appear most often in rule filters.
Top indicator values (76 distinct)
These values appear most often in rule predicates.
Exclusions (11 distinct)
These values appear most often in top-level exclusions.
Rules under this technique
These vendors publish rules tagged with this technique.
Sigma 4 rules
- New Outlook Macro Created
- Outlook Macro Execution Without Warning Setting Enabled
- Potential Persistence Via Outlook LoadMacroProviderOnBoot Setting
- Suspicious Outlook Macro Created
Elastic 1 rule
Splunk 1 rule
Kusto 11 rules
- Detect DNS queries reporting multiple errors from different clients - Anomaly Based (ASIM DNS Solution)
- Detect DNS queries reporting multiple errors from different clients - Static threshold based (ASIM DNS Solution)
- Detect excessive NXDOMAIN DNS queries - Anomaly based (ASIM DNS Solution)
- Detect excessive NXDOMAIN DNS queries - Static threshold based (ASIM DNS Solution)
- Excessive NXDOMAIN DNS Queries
- Excessive NXDOMAIN DNS Queries (ASIM DNS Schema)
- Potential DGA detected
- Potential DGA detected (ASIM DNS Schema)
- Potential DGA(Domain Generation Algorithm) detected via Repetitive Failures - Anomaly based (ASIM DNS Solution)
- Potential DGA(Domain Generation Algorithm) detected via Repetitive Failures - Static threshold based (ASIM DNS Solution)
- Squid proxy events for ToR proxies