mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
2.8 KiB
2.8 KiB
title, last_modified_at, toc, tags
| title | last_modified_at | toc | tags | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Command and Control | 2018-06-01 | true |
|
Description
Detect and investigate tactics, techniques, and procedures leveraged by attackers to establish and operate command and control channels. Implants installed by attackers on compromised endpoints use these channels to receive instructions and send data back to the malicious operators.
- ID: 943773c6-c4de-4f38-89a8-0b92f98804d8
- Product: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud
- Datamodel: Endpoint, Network_Resolution, Network_Traffic
- Last Updated: 2018-06-01
- Author: Rico Valdez, Splunk
Detection profiles
| Name | Technique | Type |
|---|---|---|
| DNS Exfiltration Using Nslookup App | None | TTP |
| DNS Query Length Outliers - MLTK | None | Anomaly |
| DNS Query Length With High Standard Deviation | None | Anomaly |
| Detect Large Outbound ICMP Packets | None | TTP |
| Detect Spike in blocked Outbound Traffic from your AWS | None | Anomaly |
| Detect hosts connecting to dynamic domain providers | None | TTP |
| Excessive DNS Failures | None | Anomaly |
| Excessive Usage of NSLOOKUP App | None | Anomaly |
| Multiple Archive Files Http Post Traffic | None | TTP |
| Plain HTTP POST Exfiltrated Data | None | TTP |
| Prohibited Network Traffic Allowed | None | TTP |
| Protocol or Port Mismatch | None | Anomaly |
| TOR Traffic | None | TTP |
Reference
- https://attack.mitre.org/wiki/Command_and_Control
- https://searchsecurity.techtarget.com/feature/Command-and-control-servers-The-puppet-masters-that-govern-malware
source | version: 1