Files
mandiant-capa-rules/communication/send-data.yml
T
2020-06-26 17:45:56 -06:00

15 lines
396 B
YAML

rule:
meta:
name: send data
namespace: communication
author: william.ballenthin@fireeye.com
description: all known techniques for sending data to a potential C2 server
scope: function
examples:
- BFB9B5391A13D0AFD787E87AB90F14F5:0x13145D60
features:
- or:
- match: send HTTP request
- match: send data on socket
- match: send file via HTTP