1200KM / detection
T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol — Detection Rules
Detection workspace for T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol: 8 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Data Exfiltration with Wget · test · medium · {"product":"linux","service":"auditd"}
- Python WebServer Execution - Linux · experimental · medium · {"product":"linux","category":"process_creation"}
- Suspicious DNS Query with B64 Encoded String · test · medium · {"category":"dns"}
- WebDav Put Request · test · low · {"product":"zeek","service":"http"}
- Suspicious Outbound SMTP Connections · test · medium · {"category":"network_connection","product":"windows"}
- PowerShell ICMP Exfiltration · test · medium · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- WebDav Client Execution Via Rundll32.EXE · test · medium · {"category":"process_creation","product":"windows"}
- Suspicious WebDav Client Execution Via Rundll32.EXE · test · high · {"category":"process_creation","product":"windows"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0149 Detection of Exfiltration Over Unencrypted Non-C2 Protocol
AN0423 Analytic 0423
Detects data access or staging events followed by outbound data flows using unencrypted protocols (e.g., FTP, HTTP) initiated by unexpected processes or to rare destinations.
AN0424 Analytic 0424
Detects file access or compression utilities followed by outbound connections using curl, wget, ftp, or custom binaries communicating over unencrypted protocols.
AN0425 Analytic 0425
Detects abnormal outbound HTTP/FTP connections by local scripts or binaries outside of standard browser activity, following access to local documents or user data.
AN0426 Analytic 0426
Detects shell-based scripts accessing configuration files or snapshots and transmitting them over unencrypted protocols such as FTP or HTTP to non-management IPs.
AN0427 Analytic 0427
Detects use of unencrypted protocols (e.g., TFTP, FTP, HTTP) to transfer configuration files, routing tables, or logs to untrusted IP addresses, especially using administrative commands like `copy run ftp:`.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.