Exfiltration Over C2 Channel T1041
Tactic: Exfiltration
Adversaries may steal data by exfiltrating it over an existing command and control channel. Stolen data is encoded into the normal communications channel using the same protocol as command and control communications.
Events covered
17 catalog events are tagged with this technique by at least one rule.
Authoring guide
These 82 rules share fields, values, and exclusions.
Fields filtered most (89 distinct)
These fields appear most often in rule filters.
Top indicator values (248 distinct)
These values appear most often in rule predicates.
Exclusions (58 distinct)
These values appear most often in top-level exclusions.
Rules under this technique
These vendors publish rules tagged with this technique.
Sigma 7 rules
- Equation Group C2 Communication
- macOS Network Upload Activity
- Network Communication Initiated To Portmap.IO Domain
- OpenCanary - TFTP Request
- Shai-Hulud NPM Package Malicious Exfiltration via Curl
- Tunneling Tool Execution
- Vice Society directory crawling script for data exfiltration (via ps_script)
Elastic 18 rules
- DNS Tunneling
- Network Activity Detected via Kworker
- Network Traffic to Rare Destination Country
- Potential Data Exfiltration Activity to an Unusual Destination Port
- Potential Data Exfiltration Activity to an Unusual IP Address
- Potential Data Exfiltration Activity to an Unusual ISO Code
- Potential Data Exfiltration Activity to an Unusual Region
- Spike in Firewall Denies
- Spike in host-based traffic
- Spike in Network Traffic
- Spike in Network Traffic To a Country
- Unusual AWS Command for a User
- Unusual Azure Activity Logs Event for a User
- Unusual GCP Event for a User
- Unusual Linux Network Activity
- Unusual Linux Network Port Activity
- Unusual Network Destination Domain Name
- Unusual Windows Network Activity
Splunk 13 rules
- Cisco ASA - Device File Copy to Remote Location
- Cisco Secure Firewall - High EVE Threat Confidence
- Cisco Secure Firewall - Intrusion Events by Threat Activity
- Cisco Secure Firewall - Lumma Stealer Download Attempt
- Cisco Secure Firewall - Lumma Stealer Outbound Connection Attempt
- Cisco Secure Firewall - Potential Data Exfiltration
- Detect SNICat SNI Exfiltration
- Potential Telegram API Request Via CommandLine
- Powershell ICMP Data Exfiltration (PowerShell)
- Script Connected to External Destination - Windows (Sysmon)
- Script Connected to External Destination - Windows (Windows Event Log)
- Windows Exfiltration Over C2 Via Invoke RestMethod
- Windows Exfiltration Over C2 Via Powershell UploadString
Kusto 32 rules
- Abnormal Deny Rate for Source IP
- Abnormal Port to Protocol
- Cisco Cloud Security - Connection to non-corporate private network
- Cisco Cloud Security - Connection to Unpopular Website Detected
- Cisco Cloud Security - Crypto Miner User-Agent Detected
- Cisco Cloud Security - Rare User Agent Detected
- Cisco Cloud Security - Request Allowed to harmful/malicious URI category
- Detect presence of private IP addresses in URLs (ASIM Web Session)
- Excessive Blocked Traffic Events Generated by User
- Files Copied to USB Drives
- High severity malicious activity detected
- IP address of Windows host encoded in web request
- Multiple Sources Affected by the Same TI Destination
- Powershell Empire Cmdlets Executed in Command Line
- RecordedFuture Threat Hunting IP All Actors
- RunningRAT request parameters
- SonicWall - Allowed SSH, Telnet, and RDP Connections
- Tailscale Premium: Large outbound transfer over tailnet
- Tailscale Premium: Subnet router throughput anomaly
- Tailscale Premium: Unexpected exit-node egress
- Ubiquiti - connection to non-corporate DNS server
- Ubiquiti - Large ICMP to external server
- Vectra Account's Behaviors
- Vectra AI Detect - Detections with High Severity
- Vectra AI Detect - Suspected Compromised Account
- Vectra AI Detect - Suspected Compromised Host
- Vectra AI Detect - Suspicious Behaviors by Category
- Vectra Host's Behaviors
- Vectra RUX - Create Incident for Escalated Account Detection or Unresolved Priority Account
- Vectra RUX - Create Incident for Escalated Host Detection or Unresolved Priority Host
- Website blocked by ESET
- Windows host username encoded in base64 web request
YARA-L 1 rule
Panther 11 rules
- Auth0 Delete Tenant Member
- GCP K8S Pod Create Or Modify Host Path Volume Mount
- Kubernetes Pod With HostPath Volume Mount
- Snowflake Data Exfiltration
- Snowflake Data Exfiltration
- Snowflake File Downloaded
- Snowflake File Downloaded
- Snowflake Table Copied Into Stage
- Snowflake Table Copied Into Stage
- Snowflake Temporary Stage Created
- Snowflake Temporary Stage Created