Files
MBCProject-mbc-markdown/command-and-control
2020-04-13 10:00:00 -04:00
..
2020-01-28 15:23:13 -05:00
2020-04-13 10:00:00 -04:00

ID M9004

Command and Control

Behaviors malware may use to communicate with systems under its control within a target network. There are many ways malware can establish command and control with various levels of covertness, depending on system configuration and network topology. Behaviors may relate to C2 servers or a bot that is part of a botnet.

  • Command and Control Communication M0030
  • Commonly Used Port T1043
  • Connection Proxy T1090
  • Custom Command and Control Protocol T1094
  • Custom Cryptographic Protocol T1024
  • Data Encoding T1132
  • Data Obfuscation T1001
  • Domain Name Generation M0031
  • Fallback Channels T1008
  • Multi-hop Proxy T1188
  • Multi-Stage Channels T1104
  • Port Knocking T1205
  • Remote Access Tools T1219
  • Remote File Copy E1105
  • Standard Application Layer Protocol T1071
  • Standard Cryptographic Protocol T1032
  • Standard Non-Application Layer Protocol T1095
  • Uncommonly Used Port T1065
  • Web Service T1102