Application Layer Protocol

T1071

Technique with 5 sub-techniques.View on attack.mitre.org

About this technique

Adversaries may communicate using OSI application layer protocols to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.

Adversaries may utilize many different protocols, including those used for web browsing, transferring files, electronic mail, DNS, or publishing/subscribing. For connections that occur internally within an enclave (such as those between a proxy or pivot node and other nodes), commonly used protocols are SMB, SSH, or RDP.

Detection rules85

Rules on DetectionCode tagged with T1071 or one of its sub-techniques.

Sigma45

RuleLevelLog sourceTechnique
Cobalt Strike DNS BeaconingcriticalNULL / dnsT1071.004
HackTool - BabyShark Agent Default URL PatterncriticalNULL / proxyT1071.001
PwnDrp AccesscriticalNULL / proxyT1071.001
Silence.EDA Detectioncriticalwindows / ps_scriptT1071.004
Suspicious Cobalt Strike DNS Beaconing - DNS Clientcriticalwindows / NULLT1071.004
Suspicious Cobalt Strike DNS Beaconing - Sysmoncriticalwindows / dns_queryT1071.004
APT User AgenthighNULL / proxyT1071.001
Bitsadmin to Uncommon IP Server AddresshighNULL / proxyT1071.001
Bitsadmin to Uncommon TLDhighNULL / proxyT1071.001
Crypto Miner User AgenthighNULL / proxyT1071.001
DNS Exfiltration and Tunneling Tools Executionhighwindows / process_creationT1071.004
DNS Query by Finger Utilityhighwindows / dns_queryT1071.004
DNS TXT Answer with Possible Execution StringshighNULL / dnsT1071.004
Exploit Framework User AgenthighNULL / proxyT1071.001
HackTool - CobaltStrike Malleable Profile Patterns - ProxyhighNULL / proxyT1071.001

Splunk40

RuleTypeRiskData sourceTechnique
Cisco NVM - Osascript Network Connection for a Long DurationAnomalyNULLCisco Network Visibility Module Flow DataT1071.001
Cisco Secure Firewall - Blacklisted SSL Certificate FingerprintTTPNULLCisco Secure Firewall Threat Defense Connection EventT1071.001
Cisco Secure Firewall - Connection to File Sharing DomainAnomalyNULLCisco Secure Firewall Threat Defense Connection EventT1071.001
Cisco Secure Firewall - High EVE Threat ConfidenceAnomalyNULLCisco Secure Firewall Threat Defense Connection EventT1071.001
Cisco Secure Firewall - High Priority Intrusion ClassificationTTPNULLCisco Secure Firewall Threat Defense Intrusion EventT1071
Cisco Secure Firewall - High Volume of Intrusion Events Per HostAnomalyNULLCisco Secure Firewall Threat Defense Intrusion EventT1071
Cisco Secure Firewall - Wget or Curl DownloadAnomalyNULLCisco Secure Firewall Threat Defense Connection EventT1071.001
Detect Outbound SMB TrafficTTPNULLCisco Secure Firewall Threat Defense Connection Event, Cisco Secure Access FirewallT1071.002
Detect web traffic to dynamic domain providersTTPNULLT1071.001
DNS Kerberos CoercionTTPNULLSuricata, Sysmon EventID 22T1071.004
DNS Query Length Outliers - MLTKAnomalyNULLT1071.004
DNS Query Requests Resolved by Unauthorized DNS ServersTTPNULLT1071.004
DNS record changedTTPNULLT1071.004
Excessive DNS FailuresAnomalyNULLT1071.004
HTTP C2 Framework User AgentTTPNULLSuricataT1071.001

Sub-techniques5

IDNameExamples
T1071.001Web Protocols422
T1071.002File Transfer Protocols27
T1071.003Mail Protocols26
T1071.004DNS55
T1071.005Publish/Subscribe Protocols1

Groups5

Software10

Campaigns1

Procedure examples16

Groups5

Used byProcedure example
GroupINC Ransom

INC Ransom has used valid accounts over RDP to connect to targeted systems.

GroupMagic Hound

Magic Hound malware has used IRC for C2.

GroupRocke

Rocke issued wget requests from infected systems to the C2.

GroupTeamTNT

TeamTNT has used an IRC bot for C2 communications.

GroupVelvet Ant

Velvet Ant has used reverse SSH tunnels to communicate to victim devices.

Software10

Used byProcedure example
MalwareClambling

Clambling has the ability to use Telnet for communication.

MalwareDuqu

Duqu uses a custom command and control protocol that communicates over commonly used ports, and is frequently encapsulated by application layer protocols.

MalwareHildegard

Hildegard has used an IRC channel for C2 communications.

MalwareLucifer

Lucifer can use the Stratum protocol on port 10001 for communication between the cryptojacking bot and the mining server.

MalwareNETEAGLE

Adversaries can also use NETEAGLE to establish an RDP connection with a controller over TCP/7519.

MalwareNightdoor

Nightdoor uses TCP and UDP communication for command and control traffic.

MalwareQUIETEXIT

QUIETEXIT can use an inverse negotiated SSH connection as part of its C2.

MalwareRaspberry Robin

Raspberry Robin is capable of contacting the TOR network for delivering second-stage payloads.

View all 10 software examples

Campaigns1

Used byProcedure example
CampaignFrostyGoop Incident

During FrostyGoop Incident, the adversary initiated Layer Two Tunnelling Protocol (L2TP) connections to Moscow-based IP addresses.

References1

  1. Mandiant APT29 Eye Spy Email Nov 22 Open source
    Mandiant. (2022, May 2). UNC3524: Eye Spy on Your Email. Retrieved August 17, 2023.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.