1200kmSECURITY RESEARCH
Loading interactive filters…

1200KM / detection

T1048 Exfiltration Over Alternative Protocol — Detection Rules

Detection workspace for T1048 Exfiltration Over Alternative Protocol: 9 Sigma sources, 1 Atlas concepts and 0 anomaly models. No live detection validation.

Source-backed rule directory

Atlas deterministic concepts

T1048 Exfiltration Over Alternative Protocol

MATCH(outbound_protocol NOT_IN approved_protocols) AND outbound_bytes >= threshold -> ALERT

Anomaly models

No exact Atlas model in this snapshot.

ATT&CK analytic guidance

DET0131 Behavioral Detection Strategy for Exfiltration Over Alternative Protocol

AN0367 Analytic 0367

Detects unusual outbound file transfer behavior using protocols like FTP, SMB, SMTP, or DNS, involving non-standard processes, off-hour activity, or uncommonly high volume.

AN0368 Analytic 0368

Detects file exfiltration using tools like curl, scp, or custom binaries over protocols such as FTP, HTTP/S, or DNS tunneling, especially outside baseline user behavior.

AN0369 Analytic 0369

Detects non-native file transfer via curl, Python scripts, or AppleScript using uncommon protocols like FTP, SMTP, or DNS exfiltration through mDNSResponder abuse.

AN0370 Analytic 0370

Detects access to cloud APIs or CLI tools to move or sync files from sensitive buckets to external endpoints using protocols like HTTPS or S3 APIs.

AN0371 Analytic 0371

Detects outbound traffic from hostd/vpxa or guest VM interfaces using unauthorized protocols such as FTP, HTTP POST bursts, or long-lived DNS tunnels.

Connected ecosystem references

Linked tags

Simulation, tools and telemetry

T1048 simulation workspace

Threat actor context

These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.

Existing anomaly research

Original publication snapshot · Anomaly Detection Atlas

Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.