1200kmSECURITY RESEARCH
Loading interactive filters…

1200KM / detection

T1041 Exfiltration Over C2 Channel — Detection Rules

Detection workspace for T1041 Exfiltration Over C2 Channel: 2 Sigma sources, 1 Atlas concepts and 1 anomaly models. No live detection validation.

Source-backed rule directory

Atlas deterministic concepts

T1041 Exfiltration Over C2 Channel

SUM(outbound_bytes BY source_host AND destination, 15m) >= threshold AND destination NOT_IN approved_destinations -> ALERT

Anomaly models

ATT&CK analytic guidance

DET0348 Detection Strategy for Exfiltration Over C2 Channel

AN0988 Analytic 0988

Identifies suspicious outbound traffic volume mismatches from processes that typically do not generate network activity, particularly over C2 protocols like HTTPS, DNS, or custom TCP/UDP ports, following file or data access.

AN0989 Analytic 0989

Monitors for processes reading sensitive files then immediately initiating unusual outbound connections or bulk transfer sessions over persistent sockets, particularly with encrypted or binary payloads.

AN0990 Analytic 0990

Detects unauthorized applications or scripts accessing sensitive data followed by establishing encrypted outbound communication to rare external destinations or with abnormal byte ratios.

AN0991 Analytic 0991

Detects VMs sending outbound traffic through non-standard services or to unknown destinations. Exfiltration over reverse shells tunneled via VMkernel or custom payloads routed via hostd/vpxa.

Connected ecosystem references

Linked tags

Simulation, tools and telemetry

T1041 simulation workspace

Threat actor context

These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.

Existing anomaly research

Original publication snapshot · Anomaly Detection Atlas

Connected anomaly research

Curated research views reached through an exact source technique, a catalog model, or a reviewed collection reference. These are navigation associations, not claims of detector effectiveness or sensor equivalence.

Telemetry contracts · Maintained query examples · Validation and blind spots

Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.