1200KM / detection
T1048 Exfiltration Over Alternative Protocol — Detection Rules
Detection workspace for T1048 Exfiltration Over Alternative Protocol: 9 Sigma sources, 1 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- DNS TOR Proxies · test · medium · {"service":"dns","product":"zeek"}
- Tap Driver Installation - Security · test · low · {"product":"windows","service":"security","definition":"Requirements: The System Security Extension audit subcategory need to be enabled to log the EID 4697"}
- Tap Driver Installation · test · medium · {"product":"windows","service":"system"}
- Powershell DNSExfiltration · test · high · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- Data Export From MSSQL Table Via BCP.EXE · test · medium · {"category":"process_creation","product":"windows"}
- PUA - Restic Backup Tool Execution · experimental · high · {"product":"windows","category":"process_creation"}
- Copy From Or To Admin Share Or Sysvol Folder · test · medium · {"category":"process_creation","product":"windows"}
- Suspicious Redirection to Local Admin Share · test · high · {"category":"process_creation","product":"windows"}
- Tap Installer Execution · test · medium · {"category":"process_creation","product":"windows"}
Atlas deterministic concepts
T1048 Exfiltration Over Alternative Protocol
MATCH(outbound_protocol NOT_IN approved_protocols) AND outbound_bytes >= threshold -> ALERTAnomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0131 Behavioral Detection Strategy for Exfiltration Over Alternative Protocol
AN0367 Analytic 0367
Detects unusual outbound file transfer behavior using protocols like FTP, SMB, SMTP, or DNS, involving non-standard processes, off-hour activity, or uncommonly high volume.
AN0368 Analytic 0368
Detects file exfiltration using tools like curl, scp, or custom binaries over protocols such as FTP, HTTP/S, or DNS tunneling, especially outside baseline user behavior.
AN0369 Analytic 0369
Detects non-native file transfer via curl, Python scripts, or AppleScript using uncommon protocols like FTP, SMTP, or DNS exfiltration through mDNSResponder abuse.
AN0370 Analytic 0370
Detects access to cloud APIs or CLI tools to move or sync files from sensitive buckets to external endpoints using protocols like HTTPS or S3 APIs.
AN0371 Analytic 0371
Detects outbound traffic from hostd/vpxa or guest VM interfaces using unauthorized protocols such as FTP, HTTP POST bursts, or long-lived DNS tunnels.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.