Application Layer Protocol T1071
Tactic: Command & Control
Adversaries may communicate using OSI application layer protocols to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.
Events covered
47 catalog events are tagged with this technique by at least one rule.
Authoring guide
These 506 rules share fields, values, and exclusions.
Fields filtered most (370 distinct)
These fields appear most often in rule filters.
Top indicator values (4853 distinct)
These values appear most often in rule predicates.
Exclusions (2364 distinct)
These values appear most often in top-level exclusions.
Rules under this technique
These vendors publish rules tagged with this technique.
Sigma 70 rules
- APT User Agent
- APT40 Dropbox Tool User Agent
- Axios NPM Compromise Malicious C2 Domain DNS Query
- Bitsadmin to Uncommon IP Server Address
- Bitsadmin to Uncommon TLD
- Chafer Malware URL Pattern
- Change User Agents with WebRequest
- Cloudflared Tunnels Related DNS Requests
- Cobalt Strike DNS Beaconing
- ComRAT Network Communication
- Crypto Miner User Agent
- Curl.EXE Execution With Custom UserAgent
- DNS Exfiltration and Tunneling Tools Execution
- DNS Query by Finger Utility
- DNS Query Request By QuickAssist.EXE
- DNS Query To Common Malware Hosting and Shortener Services
- DNS Query To Devtunnels Domain
- DNS Query To Katz Stealer Domains
- DNS Query To Katz Stealer Domains - Network
- DNS Query To Visual Studio Code Tunnels Domain
- DNS TXT Answer with Possible Execution Strings
- DoT (DNS over TLS) activation (command)
- DoT (DNS over TLS) activation (PowerShell)
- Exploit Framework User Agent
- GALLIUM Artefacts - Builtin
- GALLIUM IOCs
- Github Self-Hosted Runner Execution
- HackTool - BabyShark Agent Default URL Pattern
- HackTool - CobaltStrike Malleable Profile Patterns - Proxy
- HackTool - Empire UserAgent URI Combo
- HackTool - SILENTTRINITY Stager DLL Load
- HackTool - SILENTTRINITY Stager Execution
- HTTP Request With Empty User Agent
- Kalambur Backdoor Curl TOR SOCKS Proxy Execution
- Katz Stealer Suspicious User-Agent
- Low Reputation Effective Top-Level Domain (eTLD)
- macOS DNS Query Tools for C2
- macOS HTTP Tools with Protocol Indicators
- macOS Network Utility Tools for C2
- Malware User Agent
- Network Connection Initiated via Finger.EXE
- OilRig APT Activity
- OilRig APT Registry Persistence
- OilRig APT Schedule Task Persistence - Security
- OilRig APT Schedule Task Persistence - System
- Outbound Network Connection Initiated By Microsoft Dialer
- Potential Base64 Encoded User-Agent
- Potentially Suspicious Rundll32.EXE Execution of UDL File
- PwnDrp Access
- Raw Paste Service Access
- Renamed Visual Studio Code Tunnel Execution
- Silence.EDA Detection
- Suspicious Base64 Encoded User-Agent
- Suspicious Cobalt Strike DNS Beaconing - DNS Client
- Suspicious Cobalt Strike DNS Beaconing - Sysmon
- Suspicious Curl Change User Agents - Linux
- Suspicious DNS Query with B64 Encoded String
- Suspicious Installer Package Child Process
- Suspicious User Agent
- TanStack Supply-Chain Attack DNS Indicators
- Telegram API Access
- Tunneling Tool Execution
- Ursnif Malware C2 URL Pattern
- Ursnif Malware Download URL Pattern
- Visual Studio Code Tunnel Execution
- Visual Studio Code Tunnel Service Installation
- Visual Studio Code Tunnel Shell Execution
- Wannacry Killswitch Domain
- Windows PowerShell User Agent
- Windows WebDAV User Agent
Elastic 196 rules
- Accepted Default Telnet Port Connection
- Apple Script Execution followed by Network Connection
- At Utility Launched through Udevadm
- Background Task Execution via a Hidden Process
- Bind Shell via Netcat Traditional
- Bind Shell via Node
- Bind Shell via Socket
- Cobalt Strike Command and Control Beacon
- Command Interpreter with IP Address Argument
- Connection to a Suspicious URL
- Connection to Commonly Abused Web Services
- Connection to Dynamic DNS Provider by a Signed Binary Proxy
- Connection to Dynamic DNS Provider by an Unsigned Binary
- Connection to External Network via Telnet
- Connection to WebService by a Signed Binary Proxy
- Connection to WebService by an Unsigned Binary
- Curl or Wget Spawned via Node.js
- Curl to Telegram API
- Default Cobalt Strike Team Server Certificate
- Deprecated - SUNBURST Command and Control Activity
- DNS Over HTTPS by an Unusual Process
- DNS Query to Suspicious Top Level Domain
- DNS Request by Recently Created Executable
- DNS Request by Suspicious Process Executable
- DNS Request to Crypto Miner Service
- DNS Request to Crypto/DHT Services
- DNS Request to Dynamic DNS via Suspicious Executable
- DNS Request to IP Lookup Service from Suspicious Working Directory
- DNS Request to Suspicious File Upload/Download Service
- DNS Request to Suspicious Top Level Domain
- DNS to Commonly Abused Web Services
- DNS Tunneling
- Egress Connection from Entrypoint in Container
- Egress Network Connection by MOTD Child
- Egress Network Connection Followed by Command Execution
- Egress Network Connection from Default DPKG Directory
- Egress Network Connection from Deleted Executable by Root
- Egress Network Connection from Node.js Descendant
- Egress Network Connection from RPM Package
- Entra ID Protection - Risk Detection - Sign-in Risk
- Entra ID Protection - Risk Detection - User Risk
- Execution via OpenClaw Agent
- File Creation and Execution Detected via Defend for Containers
- File Download Detected via Defend for Containers
- File Download from Suspicious Top Level Domain
- GenAI Process Connection to Suspicious Top Level Domain
- GenAI Process Connection to Unusual Domain
- Git Hook Egress Network Connection
- Git Repository or File Download to Suspicious Directory
- Halfbaked Command and Control Beacon
- Hidden Process Execution followed by Network Connection
- High Number of Egress Network Connections from Unusual Executable
- Java Dropped and Executed With DNS Lookup
- Javascript Reverse Shell via Node.js
- Linux Reverse Shell
- Linux Reverse Shell via Child
- Linux Reverse Shell via netcat
- Linux Reverse Shell via setsid and nohup
- Linux Reverse Shell via Suspicious Utility
- Linux Reverse Shell via Xterm
- Linux Suspicious Child Process Execution via Interactive Shell
- Linux Telegram API Request
- Machine Learning Detected a DNS Request Predicted to be a DGA Domain
- Machine Learning Detected a DNS Request With a High DGA Probability Score
- Machine Learning Detected DGA activity using a known SUNBURST DNS domain
- MsBuild Making Network Connections
- Netcat Reverse Shell via Busybox
- Network Activity to a Suspicious Top Level Domain
- Network Connection Followed by File Creation
- Network Connection from Binary with RWX Memory Region
- Network Connection via Compiled HTML File
- Network Connection via Recently Compiled Executable
- Network Traffic to Rare Destination Country
- Openssl Client or Server Activity
- OpenSSL Reverse Shell Activity via Named Pipe
- Outbound Network Connection Followed by Process File Deletion
- Outlook Home Page Registry Modification
- PANW and Elastic Defend - Command and Control Correlation
- Payload Downloaded and Piped to Interpreter
- Payload Downloaded by Interpreter and Piped to Interpreter
- Payload Downloaded via Curl or Wget by Web Server
- Payload Execution by Node.js Web Server
- Payload Execution by Web Server
- Payload Execution via Shell Pipe Detected by Defend for Containers
- Perl Outbound Network Connection
- Possible FIN7 DGA Command and Control Behavior
- Possible JAVA Reverse Shell
- Potential Command and Control via Internet Explorer
- Potential Command and Control via Windows Scripts
- Potential DGA Activity
- Potential DNS Tunneling via NsLookup
- Potential File Transfer via Certreq
- Potential File Transfer via Curl for Windows
- Potential Gsocket Activity
- Potential Linux Reverse Shell via Java JAR Execution
- Potential Linux Reverse Shell via Java Shell Execution
- Potential Linux Tunneling and/or Port Forwarding
- Potential Malware-Driven SSH Brute Force Attempt
- Potential Meterpreter Reverse Shell
- Potential Python Reverse Shell
- Potential Remote Code Execution via Database Server
- Potential Remote Code Execution via Langflow
- Potential Remote Code Execution via Mail Server
- Potential Remote Code Execution via URL Encoded Payload
- Potential Reverse Shell
- Potential Reverse Shell Activity via TCP/UDP Socket
- Potential Reverse Shell Activity via Terminal
- Potential Reverse Shell via Background Process
- Potential Reverse Shell via Child
- Potential Reverse Shell via Java
- Potential Reverse Shell via Java
- Potential Reverse Shell via Named Pipe
- Potential Reverse Shell via Powershell
- Potential Reverse Shell via Suspicious Binary
- Potential Reverse Shell via Suspicious Child Process
- Potential Reverse Shell via UDP
- Python Network Connection Followed by Command Execution
- Recently Downloaded File Made Executable and Run
- Reverse or Bind Shell via Suspicious Utility
- Reverse Shell via NetworkManager Dispatcher Script
- Root Network Connection via GDB CAP_SYS_PTRACE
- Script DNS Query to Managed Kubernetes Cluster
- Script Executed Through Unusual Parent Process
- Scripting or Unsigned Binary Performing DNS Lookups to Ethereum RPC Providers
- Service Communication via Mail Protocol
- Service Created by Suspicious Process and Activated
- Shell Execution via Java Parent Process
- Shell via NetworkManager Dispatcher Script
- Simple HTTP Web Server Connection
- Simple HTTP Web Server Creation
- SMTP to the Internet on Port 26/TCP
- Socat Reverse Shell or Listener Activity
- Spike in Firewall Denies
- Spike in host-based traffic
- Spike in Network Traffic To a Country
- Statistical Model Detected C2 Beaconing Activity
- Statistical Model Detected C2 Beaconing Activity with High Confidence
- Suricata and Elastic Defend Network Correlation
- Suspicious Command and Control via Internet Explorer
- Suspicious Command Execution via Busybox Proxy
- Suspicious Command Prompt Network Connection
- Suspicious Communication via Mail Protocol
- Suspicious Curl from macOS Application
- Suspicious Curl to Google App Script Endpoint
- Suspicious DNS Query by MSIEXEC
- Suspicious DNS Query from Mounted Virtual Disk
- Suspicious Echo Execution
- Suspicious Execution from a WebDav Share
- Suspicious Execution from a Windows Script
- Suspicious Execution via a Hidden Process
- Suspicious Execution via setsid and nohup
- Suspicious File Creation via Web Server
- Suspicious File Downloaded by Curl/Wget and Piped to Interpreter
- Suspicious Hidden Executable and Immediate Network Connection
- Suspicious Installer Package Spawns Network Event
- Suspicious Interpreter Execution Detected via Defend for Containers
- Suspicious Named Pipe Creation
- Suspicious Netcat Execution
- Suspicious Network Activity to the Internet by Previously Unknown Executable
- Suspicious Network Connection to Gmail via Nodejs
- Suspicious Network Connection via Installer Package
- Suspicious PHP Script Execution
- Suspicious Process Execution Detected via Defend for Containers
- Suspicious Shell Command Execution via Node.js Parent
- Suspicious Shell Execution via Java Application
- Suspicious Terraform Provider Execution and Network Connection
- Suspicious URL as argument to Self-Signed Binary
- Suspicious Web Server Child Process
- System Path File Creation and Execution Detected via Defend for Containers
- System Public IP Discovery via DNS Query
- System Reconnaissance from Unsigned Parent Followed by Network Connection
- Udev Execution Followed by Egress Network Connection
- Uncommon DNS Request via Bun or Node.js
- Unusual Child Execution via Web Server
- Unusual Command Execution via Cron
- Unusual Command Execution via Systemd Scheduled Task
- Unusual Command Execution via Web Server
- Unusual DNS Activity
- Unusual File Creation by Web Server
- Unusual File Creation via Web Server
- Unusual Linux Network Activity
- Unusual Linux Network Port Activity
- Unusual Network Connection to Suspicious Top Level Domain
- Unusual Network Connection to Suspicious Web Service
- Unusual Network Connection via DllHost
- Unusual Network Connection via RunDLL32
- Unusual Network Destination Domain Name
- Unusual Web Request
- Unusual Web User Agent
- Unusual Windows Network Activity
- URL as argument to Python Script and Immediate Network Connection
- URL as Process Argument via Installer Package
- Web Server Exploitation Detected via Defend for Containers
- Web Server Potential Command Injection Request
- Web Server Potential SQL Injection Request
- World Writeable Directory File Creation and Outbound Connection
Splunk 47 rules
- BitsAdmin NetCat PowerCat File Transfer (PowerShell)
- BitsAdmin NetCat PowerCat File Transfer (Sysmon)
- BitsAdmin NetCat PowerCat File Transfer (Windows Event Log)
- Cisco Secure Firewall - Blacklisted SSL Certificate Fingerprint
- Cisco Secure Firewall - Connection to File Sharing Domain
- Cisco Secure Firewall - High EVE Threat Confidence
- Cisco Secure Firewall - High Priority Intrusion Classification
- Cisco Secure Firewall - High Volume of Intrusion Events Per Host
- Cisco Secure Firewall - Wget or Curl Download
- Command and Control Detection (Sysmon)
- Command and Control Detection (Windows Event Log)
- Detect Outbound SMB Traffic
- DNS Kerberos Coercion
- Excessive DNS Failures
- HTTP C2 Framework User Agent
- HTTP Duplicated Header
- HTTP Malware User Agent
- HTTP Possible Request Smuggling
- HTTP PUA User Agent
- HTTP Rapid POST with Mixed Status Codes
- HTTP Request to Reserved Name on IIS Server
- HTTP RMM User Agent
- HTTP Scripting Tool User Agent
- Unexpected Network Connection from System Process (Sysmon)
- Unexpected Network Connection from System Process (Windows Event Log)
- Unusual HTTP Download (Sysmon)
- Visual Studio Code Tunnel Execution (PowerShell)
- Visual Studio Code Tunnel Execution (Sysmon)
- Visual Studio Code Tunnel Execution (Windows Event Log)
- Windows AI Platform DNS Query
- Windows App Layer Protocol Qakbot NamedPipe
- Windows App Layer Protocol Wermgr Connect To NamedPipe
- Windows Application Layer Protocol RMS Radmin Tool Namedpipe
- Windows ConvertTo-AADIntBackdoor Execution Via PowerShell Script
- Windows Credential Target Information Structure in Commandline
- Windows DNS Query Request by Telegram Bot API
- Windows File Transfer Protocol In Non-Common Process Path
- Windows FTP Exfiltration (PowerShell)
- Windows FTP Exfiltration (Sysmon)
- Windows FTP Exfiltration (Windows Event Log)
- Windows Kerberos Coercion via DNS
- Windows Mail Protocol In Non-Common Process Path
- Windows Multi hop Proxy TOR Website Query
- Windows Non-System Process Querying Definition Update
- Windows Powershell Commands from DNS TXT
- Windows Short Lived DNS Record
- Windows Visual Basic Commandline Compiler DNSQuery
Kusto 186 rules
- Anomaly found in Network Session Traffic (ASIM Network Session schema)
- ApexOne - C&C callback events
- Beacon Traffic Based on Common User Agents Visiting Limited Number of Domains
- Cisco Cloud Security - Connection to Unpopular Website Detected
- Cisco Cloud Security - Crypto Miner User-Agent Detected
- Cisco Cloud Security - Rare User Agent Detected
- Cisco Cloud Security - Request Allowed to harmful/malicious URI category
- Cisco Cloud Security - URI contains IP address
- Cisco SDWAN - Monitor Critical IPs
- Cisco SE - Connection to known C2 server
- Cloudflare - Unexpected POST requests
- Cloudflare - Unexpected POST requests
- CloudNGFW By Palo Alto Networks - Threat signatures from Unusual IP addresses
- Conditional Access - A Conditional Access app exclusion has changed
- Darktrace Model Alert
- Detect instances of multiple client errors occurring within a brief period of time (ASIM Web Session)
- Detect known risky user agents (ASIM Web Session)
- Detect potential file enumeration activity (ASIM Web Session)
- Detect potential presence of a malicious file with a double extension (ASIM Web Session)
- Detect presence of private IP addresses in URLs (ASIM Web Session)
- Detect requests for an uncommon resources on the web (ASIM Web Session)
- Detect URLs containing known malicious keywords or commands (ASIM Web Session)
- Discord CDN Risky File Download
- Discord CDN Risky File Download (ASIM Web Session Schema)
- Europium - Hash and IP IOCs - September 2022
- Fortinet - Beacon pattern detected
- GCP Audit Logs - DNSSEC Disabled on Managed DNS Zone
- GCP Security Command Center - Detect DNSSEC disabled for DNS zones
- Google SecOps - GCTI Threat Intelligence Finding
- Google Threat Intelligence - Threat Hunting Domain
- Google Threat Intelligence - Threat Hunting IP
- GreyNoise TI Map IP Entity to CommonSecurityLog
- GreyNoise TI Map IP Entity to DnsEvents
- GreyNoise TI map IP entity to Network Session Events (ASIM Network Session schema)
- GreyNoise TI map IP entity to OfficeActivity
- GreyNoise TI Map IP Entity to SigninLogs
- GSA - TI Domain Entity
- GSA - TI IP Entity
- GSA - TI URL Entity
- HoneyLabs TI Map IP Entity to CommonSecurityLog
- HoneyLabs TI Map IP Entity to Network Session (ASIM)
- HoneyLabs TI Map URL Entity to CommonSecurityLog
- iboss - Command-and-Control Detected
- IP address of Windows host encoded in web request
- Known Forest Blizzard group domains - July 2019
- Linked Malicious Storage Artifacts
- Log4j vulnerability exploit aka Log4Shell IP IOC
- Lumen TI domain in DnsEvents
- Lumen TI IPAddress in CommonSecurityLog
- Lumen TI IPAddress in DeviceEvents
- Lumen TI IPAddress in IdentityLogonEvents
- Lumen TI IPAddress in OfficeActivity
- Lumen TI IPAddress in SecurityEvents
- Lumen TI IPAddress in SigninLogs
- Lumen TI IPAddress in WindowsEvents
- Malformed user agent
- McAfee ePO - Firewall disabled
- Mercury - Domain, Hash and IP IOCs - August 2022
- Multiple Sources Affected by the Same TI Destination
- Netskope - Suspicious Network Context (Unusual IPs/Geo/Ports)
- New UserAgent observed in last 24 hours
- Outgoing connection attempts stateful anomaly on database
- Palo Alto - potential beaconing detected
- Palo Alto - potential beaconing detected
- Palo Alto Threat signatures from Unusual IP addresses
- Pathlock TDnR - SAP HTTP Webserver Events
- Pathlock TDnR - SAP RFC Gateway Events
- Pathlock TDnR - SAP Web Dispatcher HTTP Events
- Potential beaconing activity (ASIM Network Session schema)
- Powershell Empire Cmdlets Executed in Command Line
- Preview - TI map Domain entity to Cloud App Events
- Preview - TI map IP entity to Cloud App Events
- Preview - TI map URL entity to Cloud App Events
- Request for single resource on domain
- Risky user signin observed in non-Microsoft network device
- RunningRAT request parameters
- Several deny actions registered
- SlackAudit - Unknown User Agent
- SpyCloud infostealer malware credential exposure
- SUPERNOVA webshell
- Tailscale Premium: Network flow beaconing detected
- The download of potentially risky files from the Discord Content Delivery Network (CDN) (ASIM Web Session)
- Threat Connect TI map Domain entity to DnsEvents
- ThreatConnect TI map Email entity to OfficeActivity
- ThreatConnect TI map Email entity to SigninLogs
- ThreatConnect TI map IP entity to Network Session Events (ASIM Network Session schema)
- ThreatConnect TI Map URL Entity to OfficeActivity Data
- TI Map Domain entity to Cloud App Events
- TI Map Domain Entity to DeviceNetworkEvents
- TI Map Domain Entity to DeviceNetworkEvents
- TI Map Domain entity to Dns Events (ASIM DNS Schema)
- TI map Domain entity to Dns Events (ASIM DNS Schema)
- TI Map Domain entity to DnsEvents
- TI map Domain entity to DnsEvents
- TI Map Domain entity to PaloAlto
- TI map Domain entity to PaloAlto
- TI Map Domain entity to PaloAlto CommonSecurityLog
- TI map Domain entity to PaloAlto CommonSecurityLog
- TI Map Domain entity to SecurityAlert
- TI map Domain entity to SecurityAlert
- TI Map Domain entity to Syslog
- TI map Domain entity to Syslog
- TI Map Domain entity to Web Session Events (ASIM Web Session schema)
- TI map Domain entity to Web Session Events (ASIM Web Session schema)
- TI Map File Hash to CommonSecurityLog Event
- TI map File Hash to CommonSecurityLog Event
- TI Map File Hash to DeviceFileEvents Event
- TI map File Hash to DeviceFileEvents Event
- TI Map File Hash to Security Event
- TI map File Hash to Security Event
- TI Map IP entity to AppServiceHTTPLogs
- TI map IP entity to AppServiceHTTPLogs
- TI Map IP entity to AWSCloudTrail
- TI map IP entity to AWSCloudTrail
- TI Map IP entity to Azure Key Vault logs
- TI map IP entity to Azure Key Vault logs
- TI Map IP Entity to Azure SQL Security Audit Events
- TI Map IP Entity to Azure SQL Security Audit Events
- TI Map IP Entity to AzureActivity
- TI Map IP Entity to AzureActivity
- TI Map IP entity to AzureFirewall
- TI map IP entity to AzureFirewall
- TI Map IP entity to AzureNetworkAnalytics_CL (NSG Flow Logs)
- TI map IP entity to AzureNetworkAnalytics_CL (NSG Flow Logs)
- TI Map IP entity to Cloud App Events
- TI Map IP Entity to CommonSecurityLog
- TI Map IP Entity to CommonSecurityLog
- TI Map IP Entity to DeviceNetworkEvents
- TI Map IP Entity to DeviceNetworkEvents
- TI Map IP entity to DNS Events (ASIM DNS schema)
- TI map IP entity to DNS Events (ASIM DNS schema)
- TI Map IP Entity to DnsEvents
- TI Map IP Entity to DnsEvents
- TI Map IP Entity to Duo Security
- TI Map IP Entity to Duo Security
- TI Map IP entity to GitHub_CL
- TI map IP entity to GitHub_CL
- TI Map IP entity to Network Session Events (ASIM Network Session schema)
- TI map IP entity to Network Session Events (ASIM Network Session schema)
- TI Map IP entity to OfficeActivity
- TI map IP entity to OfficeActivity
- TI Map IP Entity to SigninLogs
- TI Map IP Entity to SigninLogs
- TI Map IP Entity to VMConnection
- TI Map IP Entity to VMConnection
- TI Map IP Entity to W3CIISLog
- TI Map IP Entity to W3CIISLog
- TI Map IP entity to Web Session Events (ASIM Web Session schema)
- TI map IP entity to Web Session Events (ASIM Web Session schema)
- TI Map IP entity to Workday(ASimAuditEventLogs)
- TI map IP entity to Workday(ASimAuditEventLogs)
- TI Map URL Entity to AuditLogs
- TI Map URL Entity to AuditLogs
- TI Map URL entity to Cloud App Events
- TI Map URL Entity to DeviceNetworkEvents
- TI Map URL Entity to DeviceNetworkEvents
- TI Map URL Entity to EmailUrlInfo
- TI Map URL Entity to EmailUrlInfo
- TI Map URL Entity to OfficeActivity Data [Deprecated]
- TI Map URL Entity to PaloAlto Data
- TI Map URL Entity to PaloAlto Data
- TI Map URL Entity to SecurityAlert Data
- TI Map URL Entity to SecurityAlert Data
- TI Map URL Entity to Syslog Data
- TI Map URL Entity to Syslog Data
- TI Map URL Entity to UrlClickEvents
- TI Map URL Entity to UrlClickEvents
- TI Map URL entity to Web Session Events (ASIM Web Session schema)
- Ubiquiti - Connection to known malicious IP or C2
- Ubiquiti - Possible connection to cryptominning pool
- Ubiquiti - Unusual FTP connection to external server
- UniFi Site Manager: Controller Connection State Change
- User Accessed Suspicious URL Categories
- Vectra Account's Behaviors
- Vectra AI Detect - Detections with High Severity
- Vectra AI Detect - New Campaign Detected
- Vectra AI Detect - Suspected Compromised Account
- Vectra AI Detect - Suspected Compromised Host
- Vectra AI Detect - Suspicious Behaviors by Category
- Vectra Host's Behaviors
- Vectra RUX - Create Incident for Escalated Account Detection or Unresolved Priority Account
- Vectra RUX - Create Incident for Escalated Host Detection or Unresolved Priority Host
- Web sites blocked by Eset
- Website blocked by ESET
- Whisper Security - C2 Communication Detection
- Windows host username encoded in base64 web request