Exfiltration Over Alternative Protocol T1048

Tactic: Exfiltration

Adversaries may steal data by exfiltrating it over a different protocol than that of the existing command and control channel. The data may also be sent to an alternate network location from the main command and control server.

Events covered

18 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 130 rules share fields, values, and exclusions.

Fields filtered most (145 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
CommandLine30contains 15, regex_match 15, in 3, wildcard 3, match 1(?i)\s--(form|upload-file|data)\s|\s--data-, (?i)ftp\s+(.{1,})?\-s\:.{1,}\.\w{2,5}, \s-[dTF]\s, (?i)(davclnt.dll.*DavSetCookie.*://\d{1,3}\.\d{1,3}\.\d{1..., (?i)\s+(((copy|move|moveto|copyto)\s+.*\S+:\S+\s+.*\S+:\S...
process_name26eq 13, in 8, regex_match 4, ne 1curl, wget, (?i)\x5ccurl\.exe, (?i)rclone, bash
EventID23eq 234688, 1, 4104, 4103, FileDownloaded
EventType17eq 12, in 6exec, ProcessRollup2, exec_event, executed, FileBlocked
event.type15eq 15start, creation
Image11ends_with 11, contains 4, starts_with 2\rundll32.exe, \winscp.exe, /python, /python2, /python2.
process.args11is_not_null 4, starts_with 4, wildcard 3, in 2, eq 1-*e*, -*l*, -*p*, --body-file, --post-data
OriginalFileName8eq 8rundll32.exe, winscp.exe, bcp.exe, bitsadmin.exe, cmd.exe
Type8eq 8account, ip
host.os.type8eq 8
sourcetype8eq 8stream:http, bash_history, cisco:asa, cisco:sfw:estreamer, gsuite:gmail:bigquery
DataSource6eq 6OUTBOUND_SMTP_MAIL, RAL_DATA, SAST_DO, SE16N_CHANGEDOCS, SLG1_ODATA
NetworkApplicationProtocol6eq 5, in 1smtp, http, https
event.category6eq 4, in 2network, network_traffic, process
DestinationPort5eq 2, in 2, ne 1139, 445, 0, 25, 2525

Top indicator values (709 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
event.typeeq
start
141078
EventIDeq
4688
8317
EventIDeq
1
6241
EventIDeq
4104
5269
EventIDeq
4103
3105
EventTypeeq
exec
7576
Esql.destination_host_countlt
3
44
Esql.verdictin
suspicious
44
Esql.verdictin
tp
44
EventTypein
ProcessRollup2
4117
EventTypein
exec
4201
EventTypein
exec_event
4149
EventTypein
start
4163
EventTypein
executed
398
EventTypein
process_started
383
NetworkApplicationProtocoleq
smtp
44
CommandLineregex_match
(?i)\s--(form|upload-file|data)\s|\s--data-
33
CommandLineregex_match
(?i)ftp\s+(.{1,})?\-s\:.{1,}\.\w{2,5}
33
CommandLineregex_match
.*[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}.*
38
CommandLineregex_match
\s-[dTF]\s
33
Protocoleq
tcp
326
SubjectUserNameeq
anonymous
33
process_nameeq
curl
329
process_nameeq
wget
319
src_ipin
10.0.0.0/8
316
src_ipin
172.16.0.0/12
316
src_ipin
192.168.0.0/16
316
CommandLinecontains
/transfer
22
CommandLinecontains
base64
219
CommandLinecontains
c:\windows\system32\davclnt.dll,davsetcookie
23

Exclusions (187 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
Esql.dest_hostin
0.0.0.0
4
Esql.dest_hostin
127.0.0.1
4
Esql.dest_hostin
168.63.129.16
4
Esql.dest_hostin
169.254.169.254
4
Esql.dest_hostin
::1
4
Esql.dest_hostin
acs-mirror.azureedge.net
4
Esql.dest_hostin
api.github.com
4
Esql.dest_hostin
artifacts.elastic.co
4
Esql.dest_hostin
download.elastic.co
4
Esql.dest_hostin
localhost
4
Esql.dest_hostin
login.microsoftonline.com
4
Esql.dest_hostin
management.azure.com
4
Esql.dest_hostin
mcr.microsoft.com
4
Esql.dest_hostin
packages.aks.azure.com
4
Esql.dest_hostin
packages.microsoft.com
4

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 25 rules

Elastic 26 rules

Splunk 34 rules

Kusto 38 rules

YARA-L 4 rules

Panther 3 rules