Non-Application Layer Protocol T1095

Tactic: Command & Control

Adversaries may use an OSI non-application layer protocol for communication between host and C2 server or among infected hosts within a network. The list of possible protocols is extensive. Specific examples include use of network layer protocols, such as the Internet Control Message Protocol (ICMP), transport layer protocols, such as the User Datagram Protocol (UDP), session layer protocols, such as Socket Secure (SOCKS), as well as redirected/tunneled protocols, such as Serial over LAN (SOL).

Events covered

16 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 46 rules share fields, values, and exclusions.

Fields filtered most (69 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
event.type18eq 17, in 1start, process_started
process_name17eq 9, in 8, wildcard 4, starts_with 2bash, csh, dash, awk, busybox
EventType16in 10, eq 9exec, connection_attempted, connection_accepted, ProcessRollup2, exec_event
host.os.type14eq 14
process.args11wildcard 7, contains 6, eq 5, in 3, regex_match 1, starts_with 1*/bin/*sh*, *import*pty*spawn*, *import*subprocess*call*, -*e*, -*l*
EventID8eq 81, 4104, 4688, 5156, 4625
parent_process_name8eq 4, in 4, wildcard 2, starts_with 1bash, csh, dash, socat, *.cgi
dest_ip6is_not_null 6, ne 1127.0.0.1, ::1
CommandLine5regex_match 4, contains 1, in 1(?i)(\-\-dns)?((\s+)|(\=))?((server\=)|(host\=))?((\d{1,3..., --lua-exec , --sh-exec , -l --proxy-type http , (?i)(socks\d\w?:\/\/|--(pre)?proxy)
Image4starts_with 2, ends_with 1, wildcard 1./, ./*, /bin/lua, /bin/perl, /bin/php
Protocol4eq 3, cross_field_compare 2, in 1*, NetworkProtocol, icmp, ipv6-icmp, udp
Type4eq 4Detection
process.parent.args4contains 3, wildcard 2, eq 1exec, *--port*, *-Dsolr.solr.home=*, */app/*.js*, -*l*
DstPortNumber3is_not_null 2, in 110034, 14433, 14444
Query3in 2, contains 1api.2ip.ua, api.ipify.org, canireachthe.net, dyn.com, dynu.com

Top indicator values (830 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
event.typeeq
start
171078
EventTypeeq
exec
8576
EventTypein
exec
6201
EventTypein
connection_attempted
526
EventTypein
connection_accepted
415
EventTypein
start
4163
EventTypein
ProcessRollup2
3117
EventTypein
exec_event
3149
process_namein
bash
6202
process_namein
dash
6170
process_namein
sh
6197
process_namein
zsh
6196
process_namein
csh
4159
process_namein
fish
4163
process_namein
ksh
4163
process_namein
tcsh
4156
process_namein
busybox
368
CommandLineregex_match
(?i)(\-\-dns)?((\s+)|(\=))?((server\=)|(host\=))?((\d{1,3}\.\d{1,3}\.\d{1,3}\...
33
process.argscontains
socket
38
process.argseq
-c
3107
process.argseq
-e
346
process.argseq
-r
319
process_nameeq
bash
312
process_nameeq
csh
37
process_nameeq
dash
39
process_nameeq
fish
37
process_nameeq
ksh
38
process_nameeq
sh
312
process_nameeq
tcsh
38
process_nameeq
zsh
312

Exclusions (159 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
dest_ipcidr_match
127.0.0.0/8
8
dest_ipcidr_match
169.254.0.0/16
8
dest_ipcidr_match
224.0.0.0/4
7
dest_ipcidr_match
::1
7
dest_ipcidr_match
10.0.0.0/8
3
dest_ipcidr_match
172.16.0.0/12
3
dest_ipcidr_match
192.168.0.0/16
3
dest_ipin
10.0.0.0/8
3
dest_ipin
100.64.0.0/10
3
dest_ipin
127.0.0.0/8
3
dest_ipin
169.254.0.0/16
3
dest_ipin
172.16.0.0/12
3
dest_ipin
192.0.0.0/24
3
dest_ipin
192.0.0.0/29
3
dest_ipin
192.0.0.10/32
3

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 3 rules

Elastic 20 rules

Splunk 11 rules

Kusto 11 rules

Panther 1 rule