1200KM / detection
T1008 Fallback Channels — Detection Rules
Detection workspace for T1008 Fallback Channels: 4 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- New Outlook Macro Created · test · medium · {"category":"file_event","product":"windows"}
- Suspicious Outlook Macro Created · test · high · {"category":"file_event","product":"windows"}
- Potential Persistence Via Outlook LoadMacroProviderOnBoot Setting · test · high · {"category":"registry_set","product":"windows"}
- Outlook Macro Execution Without Warning Setting Enabled · test · high · {"category":"registry_set","product":"windows"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0499 Behavioral Detection of Fallback or Alternate C2 Channels
AN1376 Analytic 1376
Establishing network connections on uncommon ports or protocols following C2 disruption or blocking. Often executed by processes that typically exhibit no network activity.
AN1377 Analytic 1377
Creation of outbound connections on alternate ports or using covert transport (e.g., ICMP, DNS) from non-network-intensive processes, following known disruption or blocked traffic.
AN1378 Analytic 1378
Outbound fallback traffic from low-profile or background launch agents using unusual protocols or destinations after primary channel inactivity.
AN1379 Analytic 1379
Outbound traffic from host management services or guest-to-host interactions over unusual interfaces (e.g., backdoor API endpoints or external VPN tunnels).
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.