Exfiltration Over Alternative Protocol: Exfiltration Over Asymmetric Encrypted Non-C2 Protocol T1048.002

Tactic: Exfiltration

Adversaries may steal data by exfiltrating it over an asymmetrically encrypted network protocol other than that of the existing command and control channel. The data may also be sent to an alternate network location from the main command and control server.

Authoring guide

These 4 rules share fields, values, and exclusions.

Fields filtered most (7 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
EventID4eq 4FileDownloaded, AnonymousLinkUsed, FileAccessed, Microsoft Graph Activity
SubjectUserName3eq 3, regex_match 2anonymous, ^urn:spo:anon#
metadata.event_type1eq 1
metadata.product_name1eq 1
metadata.vendor_name1eq 1
network.http.method1eq 1GET
network.http.response_code1eq 1302

Top indicator values (8 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
SubjectUserNameeq
anonymous
33
EventIDeq
FileDownloaded
22
EventIDeq
AnonymousLinkUsed
1
EventIDeq
FileAccessed
1
EventIDeq
Microsoft Graph Activity
120
SubjectUserNameregex_match
^urn:spo:anon#
22
network.http.methodeq
GET
114
network.http.response_codeeq
302
1

Rules under this technique

These vendors publish rules tagged with this technique.

Platform: Microsoft 365

Domain: SaaS

YARA-L 4 rules