Application Layer Protocol T1071

Tactic: Command & Control

Adversaries may communicate using OSI application layer protocols to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.

Events covered

47 catalog events are tagged with this technique by at least one rule.

ProviderEventTitle
SysmonEvent ID 1Process creation
SysmonEvent ID 3Network connection
SysmonEvent ID 7Image loaded
SysmonEvent ID 11FileCreate
SysmonEvent ID 12RegistryEvent (Object create and delete)
SysmonEvent ID 13RegistryEvent (Value Set)
SysmonEvent ID 14RegistryEvent (Key and Value Rename)
SysmonEvent ID 15FileCreateStreamHash
SysmonEvent ID 17PipeEvent (Pipe Created)
SysmonEvent ID 18PipeEvent (Pipe Connected)
SysmonEvent ID 22DNSEvent (DNS query)
SysmonEvent ID 23FileDelete (File Delete archived)
SysmonEvent ID 26FileDeleteDetected (File Delete logged)
Security-AuditingEvent ID 4662An operation was performed on an object.
Security-AuditingEvent ID 4663An attempt was made to access an object.
Security-AuditingEvent ID 4688A new process has been created.
Security-AuditingEvent ID 4698A scheduled task was created.
Security-AuditingEvent ID 5136A directory service object was modified.
Security-AuditingEvent ID 5137A directory service object was created.
Security-AuditingEvent ID 5152The Windows Filtering Platform blocked a packet.
Security-AuditingEvent ID 5154The Windows Filtering Platform has permitted an application or service to listen on a port for incoming connections.
Security-AuditingEvent ID 5155The Windows Filtering Platform has blocked an application or service from listening on a port for incoming connections.
Security-AuditingEvent ID 5156The Windows Filtering Platform has permitted a connection.
Security-AuditingEvent ID 5157The Windows Filtering Platform has blocked a connection.
Security-AuditingEvent ID 5158The Windows Filtering Platform has permitted a bind to a local port.
Security-AuditingEvent ID 5159The Windows Filtering Platform has blocked a bind to a local port.
Defender-CloudAppEventsanyCloud app activity
Defender-DeviceEventsanyDefender event
Defender-DeviceFileEventsanyFile activity
Defender-DeviceImageLoadEventsanyImage load
Defender-DeviceNetworkEventsanyNetwork activity
Defender-DeviceNetworkEventsInboundConnectionAcceptedInbound connection accepted
Defender-EmailEventsanyEmail processed
Defender-EmailUrlInfoanyEmail URL observed
Defender-UrlClickEventsanyURL click activity
ESFexecProcess Execution
ESFwriteFile Write
AppLockerEvent ID 8002FilePathBuffer was allowed to run.
AppLockerEvent ID 8003RuleAndFileData.FilePath was allowed to run but would have been prevented from running if the AppLocker policy were enforced.
AppLockerEvent ID 8005FilePathBuffer was allowed to run.
DNS-ClientEvent ID 3008DNS query is completed for the name QueryName, type QueryType, query options QueryOptions with status QueryStatus Results QueryResults.
DNSServerEvent ID 257RESPONSE_SUCCESS: TCP=TCP; InterfaceIP=InterfaceIP; Destination=Destination; AA=AA; AD=AD; QNAME=QNAME; QTYPE=QTYPE; XID=XID; DNSSEC=DNSSEC; RCODE=RCODE; Port=Port; Flags=Flags; Scop...
PowerShellEvent ID 4103Payload Context: ContextInfo User Data: UserData.
PowerShellEvent ID 4104Creating Scriptblock text (MessageNumber of MessageTotal).
PowerShellEvent ID 800Event ID 800
Service-Control-ManagerEvent ID 7045A service was installed in the system.
Sysmon-for-LinuxEvent ID 1Process Create

Authoring guide

These 506 rules share fields, values, and exclusions.

Fields filtered most (370 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
EventType159eq 139, in 31, ne 1exec, connection_attempted, start, connection_accepted, lookup_result
process_name139in 68, eq 62, starts_with 27, wildcard 24, is_not_null 6, ends_with 3, regex_match 3, contains 2, ne 1bash, csh, busybox, dash, curl
event.type131eq 131start, creation, change, connection, deletion
Image70starts_with 26, ends_with 22, wildcard 22, eq 6, contains 4, is_not_null 2, in 1/dev/shm/, ./, ./*, /boot/, /boot/*
process.args64eq 32, in 23, starts_with 17, wildcard 16, contains 9, regex_match 5, ends_with 3-c, -cl, -e, -i, -lc
CommandLine63contains 40, wildcard 23, regex_match 18, ends_with 3, is_not_null 2, length_compare 1, match 1*/dev/shm/*, */dev/tcp*, (?i)ftp\s+(.{1,})?\-s\:.{1,}\.\w{2,5}, * setsid *, --user-agent
host.os.type63eq 62, in 2
Active51eq 51true
parent_process_name49eq 30, in 18, starts_with 12, wildcard 9, ends_with 2bash, csh, apache2, dash, .
ValidUntil47is_null 47, time_range 47
IndicatorType45eq 24, in 21ipv4-addr, network-traffic, ipv6-addr, domain-name, url
QueryName45ends_with 12, is_not_null 12, wildcard 10, contains 9, starts_with 4, eq 2, in 2, ne 2, regex_match 2*.aternos.me, *.geojs.io, .000webhostapp.com, .afraid.org, *.4shared.com
EventID32eq 25, in 5, regex_match 23, 1, 22, 17, 18
ParentImage28starts_with 10, wildcard 8, ends_with 5, is_not_null 4, contains 1, in 1./, /boot/, /dev/shm/, /bin/java, /bin/node
NetworkSourceIP23is_not_null 23

Top indicator values (4853 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
event.typeeq
start
1271078
EventTypeeq
exec
93576
EventTypeeq
connection_attempted
3773
EventTypeeq
start
16391
Activeeq
true
5170
process_namein
bash
41202
process_namein
sh
41197
process_namein
zsh
41196
process_namein
dash
39170
process_namein
csh
38159
process_namein
fish
38163
process_namein
ksh
38163
process_namein
tcsh
38156
process_namein
curl
2289
process_namein
wget
1946
process_namein
busybox
1868
IndicatorTypein
ipv4-addr
2121
IndicatorTypein
network-traffic
2121
IndicatorTypein
ipv6-addr
2020
process_namewildcard
python*
1869
process_namewildcard
lua*
1432
process_namewildcard
php*
1439
EventTypein
connection_attempted
1526
EventTypein
exec
13201
process.argseq
-c
15107
Imagestarts_with
/dev/shm/
1453
Imagestarts_with
/tmp/
1458
Imagestarts_with
/var/tmp/
1456
IsActiveeq
true
1321
process_namestarts_with
python
1371

Exclusions (2364 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
dest_ipcidr_match
127.0.0.0/8
53
dest_ipcidr_match
169.254.0.0/16
53
dest_ipcidr_match
::1
47
dest_ipcidr_match
10.0.0.0/8
46
dest_ipcidr_match
172.16.0.0/12
46
dest_ipcidr_match
224.0.0.0/4
46
dest_ipcidr_match
192.168.0.0/16
45
dest_ipcidr_match
192.0.0.0/24
39
dest_ipcidr_match
192.0.2.0/24
39
dest_ipcidr_match
192.88.99.0/24
39
dest_ipcidr_match
240.0.0.0/4
39
dest_ipcidr_match
FE80::/10
39
dest_ipcidr_match
FF00::/8
39
dest_ipcidr_match
100.64.0.0/10
38
dest_ipcidr_match
192.175.48.0/24
38

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 70 rules

Elastic 196 rules

Splunk 47 rules

Kusto 186 rules

YARA-L 2 rules

Panther 5 rules