Protocol / Application Usage
Atlas home · Research path · Operational families · Anomaly models · Visual index
Consolidated 27 September 2026 from the revised publication. Source-reported incidents, proposed models, functional tests, and synthetic results remain separate evidence classes. Provenance and review scope.
Unusual use of a protocol, application function or destination for an entity.
Telemetry contract: Protocol-aware sensors, endpoint attribution and application audit, with parser/version details.
Candidate method [unvalidated until tested]: Define the feature explicitly: record types, endpoint usage, negotiated attributes or destination novelty.
Benign alternatives and limits: New clients, protocol changes and legitimate encoded identifiers can invalidate a historical baseline.

Text equivalent and full-size diagram
New clients and legitimate encoded identifiers can shift a baseline.
Historical use consists of routine application-data reads. Current use is a bulk export first observed for the account; the application and HTTPS transport are unchanged.
Candidate evidence includes API operations, parser and sensor context, and process and destination information. Encrypted flow metadata alone may not reveal the application action.
Inspect application audit or available parsed fields. Client upgrades, approved jobs and integrations are alternatives; port numbers and entropy alone are not verdicts.
Evidence tags: Network telemetry · Endpoint telemetry. Statistical forms: contextual, collective.
Browse articles and guides: Protocol / Application Usage.
Reported incidents and detection interpretations
SUNBURST in the SolarWinds supply-chain compromise
Period: 2020. Evidence: campaign reported by the cited source.
Observed [source-reported]: Mandiant decoded SUNBURST DNS subdomain formats carrying victim information and other coordination data. Mandiant: SUNBURST Additional Technical Details.
Anomaly interpretation [inferred]: Combine domain novelty, label structure and the originating process. DNS that is syntactically valid can still carry application data unrelated to normal resolution.
Telemetry to validate: Full QNAME, response details, timing and endpoint process attribution.
Boundary / competing explanation: Entropy alone is not a discriminator; the cited analysis does not establish the article's proposed numeric entropy range as a benchmark.
ATT&CK [author-mapped behavior, not actor attribution]: T1071.004 — Application Layer Protocol: DNS
OilRig-associated RDAT at a telecommunications organization
Period: April 2020 activity. Evidence: incident reported by the cited source.
Observed [source-reported]: Unit 42 analyzed RDAT deployed against a telecommunications organization, including variants with DNS tunneling over A and AAAA queries. Palo Alto Networks Unit 42: OilRig Targets Middle Eastern Telecommunications Organization and Adds Novel C2 Channel with Steganography to Its Inventory.
Anomaly interpretation [inferred]: Inspect encoded-label structure and repeated exchanges by process and domain. Restricting detection to TXT queries would miss these documented variants.
Telemetry to validate: DNS queries and responses, label lengths, per-domain patterns and endpoint context.
Boundary / competing explanation: Different RDAT variants use different channels; do not assign one DNS signature to every OilRig intrusion.
ATT&CK [author-mapped behavior, not actor attribution]: T1071.004 — Application Layer Protocol: DNS
Crosslinks: Temporal · Data Movement. Statistical foundation in the Anomaly Detection Atlas. Related research: AI Agent vs. Human with Wireshark: Six Malware PCAPs Put to the Test.
Illustrative scenarios (not additional incidents):
-
A workstation starts making large HTTPS uploads over port 8443 to an external host, even though that port and destination are not part of its normal application profile.
-
DNS traffic from a user device suddenly shifts from normal lookup behavior to long, high-entropy TXT queries consistent with tunneling or covert signaling.
-
A browser session begins using an unusual user-agent string and repeatedly calls rarely used SaaS API endpoints that the user never accessed before.
-
An internal host starts communicating over SSH on a non-standard port to multiple external systems, outside its normal administrative pattern.
-
A cloud application account that usually performs routine API reads begins using bulk export, synchronization, or token-management features rarely seen in that application context.
Apply this analytical view
These are curated conceptual links, not claims that a specific model detected the cited incidents.
Models: DNS carries command, control, or encoded data · DNS enumeration or zone-transfer attempts · Endpoint communicates periodically with external destination · Encrypted or obfuscated network channel · Web or collaboration service used as control channel · Enumeration of public web paths and APIs.
Collection references: Network Traffic Content · Network Traffic Flow · Application Log Content. These describe data components, not equivalent connectors or guaranteed fields.
Technique workspaces
Follow the exact technique ID to source rules, associated tools, collection references, and documented lab candidates. A navigation association is not live validation.
- T1071.004 DNS: detection workspace · simulation · tools: Brute Ratel C4, Cobalt Strike, Mythic