1200KM / simulation
T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol — Attack Simulation
Adversaries may steal data by exfiltrating it over an un-encrypted network protocol other than that of the existing command and control channel. The data may also be sent to an alternate network location from the main command and control server. Adversaries may opt to obfuscate this data, without the use of encryption, within network protocols that are natively unencrypted (such as HTTP, FTP, or DNS). This may include custom or publicly…
Technique description
Adversaries may steal data by exfiltrating it over an un-encrypted network protocol other than that of the existing command and control channel. The data may also be sent to an alternate network location from the main command and control server. Adversaries may opt to obfuscate this data, without the use of encryption, within network protocols that are natively unencrypted (such as HTTP, FTP, or DNS). This may include custom or publicly…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Exfiltration Over Alternative Protocol - HTTP
Procedure 1d1abbd6-a3d3-4b2e-bef5-c59293f46eff; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Python3 http.server
Procedure 3ea1f938-f80a-4305-9aa8-431bc4867313; elevation not declared required; cleanup not declared. Not executed or individually validated.
- MAZE FTP Upload
Procedure 57799bc2-ad1e-4130-a793-fb0c385130ba; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Exfiltration Over Alternative Protocol - HTTP
Procedure 6aa58451-1121-4490-a8e9-1dada3f1c68c; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Exfiltration Over Alternative Protocol - FTP - Rclone
Procedure b854eb97-bf9b-45ab-a1b5-b94e4880c56b; elevation required; cleanup not declared. Not executed or individually validated.
- Exfiltration Over Alternative Protocol - DNS
Procedure c403b5a4-b5fc-49f2-b181-d1c80d27db45; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Exfiltration Over Alternative Protocol - ICMP
Procedure dd4b4421-2e25-4593-90ae-7021947ad12e; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Exfiltration Over Alternative Protocol - SMTP
Procedure ec3a835e-adca-4c7c-88d2-853b69c11bb9; elevation not declared required; cleanup not declared. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.