Files
splunk-security_content/docs/_stories/command_and_control.md
T
2021-09-20 20:45:22 -04:00

2.8 KiB

title, last_modified_at, toc, tags
title last_modified_at toc tags
Command and Control 2018-06-01 true
Splunk Enterprise
Splunk Enterprise Security
Splunk Cloud
Endpoint
Network_Resolution
Network_Traffic

Description

Detect and investigate tactics, techniques, and procedures leveraged by attackers to establish and operate command and control channels. Implants installed by attackers on compromised endpoints use these channels to receive instructions and send data back to the malicious operators.

  • ID: 943773c6-c4de-4f38-89a8-0b92f98804d8
  • Product: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud
  • Datamodel: Endpoint, Network_Resolution, Network_Traffic
  • Last Updated: 2018-06-01
  • Author: Rico Valdez, Splunk

Detection profiles

Name Technique Type
DNS Exfiltration Using Nslookup App None TTP
DNS Query Length Outliers - MLTK None Anomaly
DNS Query Length With High Standard Deviation None Anomaly
Detect Large Outbound ICMP Packets None TTP
Detect Spike in blocked Outbound Traffic from your AWS None Anomaly
Detect hosts connecting to dynamic domain providers None TTP
Excessive DNS Failures None Anomaly
Excessive Usage of NSLOOKUP App None Anomaly
Multiple Archive Files Http Post Traffic None TTP
Plain HTTP POST Exfiltrated Data None TTP
Prohibited Network Traffic Allowed None TTP
Protocol or Port Mismatch None Anomaly
TOR Traffic None TTP

Reference

source | version: 1