1200KM / simulation
T1048 Exfiltration Over Alternative Protocol — Attack Simulation
Adversaries may steal data by exfiltrating it over a different protocol than that of the existing command and control channel. The data may also be sent to an alternate network location from the main command and control server. Alternate protocols include FTP, SMTP, HTTP/S, DNS, SMB, or any other network protocol not being used as the main command and control channel. Adversaries may also opt to encrypt and/or obfuscate these alternate channels.…
Technique description
Adversaries may steal data by exfiltrating it over a different protocol than that of the existing command and control channel. The data may also be sent to an alternate network location from the main command and control server. Alternate protocols include FTP, SMTP, HTTP/S, DNS, SMB, or any other network protocol not being used as the main command and control channel. Adversaries may also opt to encrypt and/or obfuscate these alternate channels.…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Exfiltration Over Alternative Protocol - SSH
Procedure 7c3cb337-35ae-4d06-bf03-3032ed2ec268; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Exfiltrate Data using DNS Queries via dig
Procedure a27916da-05f2-4316-a3ee-feec67a437be; elevation not declared required; cleanup not declared. Not executed or individually validated.
- DNSExfiltration (doh)
Procedure c943d285-ada3-45ca-b3aa-7cd6500c6a48; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Exfiltration Over Alternative Protocol - SSH
Procedure f6786cc8-beda-4915-a4d6-ac2f193bb988; elevation not declared required; cleanup not declared. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.