EXPLORE
← Back to Explore
T1048

Exfiltration Over Alternative Protocol

Adversaries may steal data by exfiltrating it over a different protocol than that of the existing command and control channel. The data may also be sent to an alternate network location from the main command and control server. Alternate protocols include FTP, SMTP, HTTP/S, DNS, SMB, or any other network protocol not being used as the main command and control channel. Adversaries may also opt to encrypt and/or obfuscate these alternate channels. [Exfiltration Over Alternative Protocol](http...

ESXiIaaSLinuxmacOSNetwork DevicesOffice SuiteSaaSWindows
41
Detections
4
Sources
2
Threat Actors

BY SOURCE

23elastic11sigma5splunk_escu2crowdstrike_cql

PROCEDURES (31)

Process Creation Monitoring2 detections

Auto-extracted: 2 detections for process creation monitoring

Suspicious2 detections

Auto-extracted: 2 detections for suspicious

Download2 detections

Auto-extracted: 2 detections for download

Persist2 detections

Auto-extracted: 2 detections for persist

Dns2 detections

Auto-extracted: 2 detections for dns

Ransomware1 detections

Auto-extracted: 1 detections for ransomware

Suspicious1 detections

Auto-extracted: 1 detections for suspicious

Suspicious1 detections

Auto-extracted: 1 detections for suspicious

Dns1 detections

Auto-extracted: 1 detections for dns

Service1 detections

Auto-extracted: 1 detections for service

Tunnel1 detections

Auto-extracted: 1 detections for tunnel

Remote1 detections

Auto-extracted: 1 detections for remote

Ransomware1 detections

Auto-extracted: 1 detections for ransomware

Unusual1 detections

Auto-extracted: 1 detections for unusual

Remote1 detections

Auto-extracted: 1 detections for remote

Service1 detections

Auto-extracted: 1 detections for service

Tunnel1 detections

Auto-extracted: 1 detections for tunnel

C21 detections

Auto-extracted: 1 detections for c2

Command And Control1 detections

Auto-extracted: 1 detections for command and control

Cloud1 detections

Auto-extracted: 1 detections for cloud

Dump1 detections

Auto-extracted: 1 detections for dump

Exfiltrat1 detections

Auto-extracted: 1 detections for exfiltrat

C21 detections

Auto-extracted: 1 detections for c2

Exfiltrat1 detections

Auto-extracted: 1 detections for exfiltrat

Credential1 detections

Auto-extracted: 1 detections for credential

Inject1 detections

Auto-extracted: 1 detections for inject

Command And Control1 detections

Auto-extracted: 1 detections for command and control

Suspicious1 detections

Auto-extracted: 1 detections for suspicious

Dump1 detections

Auto-extracted: 1 detections for dump

Suspicious1 detections

Auto-extracted: 1 detections for suspicious

Tunnel1 detections

Auto-extracted: 1 detections for tunnel

THREAT ACTORS (2)

DETECTIONS (41)

Copy From Or To Admin Share Or Sysvol Folder
sigmamedium
Data Export From MSSQL Table Via BCP.EXE
sigmamedium
DNS Exfiltration Using Nslookup App
splunk_escu
DNS TOR Proxies
sigmamedium
Excessive Usage of NSLOOKUP App
splunk_escu
File Transfer or Listener Established via Netcat
elasticmedium
File Transfer Utility Launched from Unusual Parent
elasticmedium
FTP Connection Open Attempt Via Winscp CLI
sigmamedium
High Volume SMB File Copy (Data Exfiltration / Ransomware) – Microsoft Defender for Identity
crowdstrike_cql
LLM-Based Curl Activity Triage
elasticmedium
LLM-Based Curl Activity Triage via Auditd
elasticmedium
LLM-Based Wget Activity Triage
elasticmedium
LLM-Based Wget Activity Triage via Auditd
elasticmedium
Netcat File Transfer or Listener Detected via Defend for Containers
elasticmedium
Network Activity Detected via cat
elasticmedium
Network Traffic to Rare Destination Country
elasticlow
O365 DLP Rule Triggered
splunk_escu
Ollama Possible Model Exfiltration Data Leakage
splunk_escu
Overnight Post-RDP Activity Detection
crowdstrike_cql
Potential Data Exfiltration Through Curl
elasticmedium
Potential Data Exfiltration Through Wget
elasticmedium
Potential Data Exfiltration via Rclone
elasticmedium
Potential Database Dumping Activity
elasticlow
Potential DNS Exfiltration via Excessive Chunked Queries
elasticmedium
Potential DNS Tunneling via Long and Unique Subdomains
elasticmedium
Powershell DNSExfiltration
sigmahigh
Prohibited Network Traffic Allowed
splunk_escu
PUA - Restic Backup Tool Execution
sigmahigh
Rare SMB Connection to the Internet
elasticmedium
SMB (Windows File Sharing) Activity to the Internet
elasticmedium
SMTP to the Internet on Port 26/TCP
elasticlow
Spike in host-based traffic
elasticlow
Spike in Network Traffic To a Country
elasticlow
Suspicious Redirection to Local Admin Share
sigmahigh
Tap Driver Installation
sigmamedium
Tap Driver Installation - Security
sigmalow
Tap Installer Execution
sigmamedium
Unusual DNS Activity
elasticlow
Unusual Windows Network Activity
elasticlow
Windows Registry File Creation in SMB Share
elasticmedium
Winscp Execution From Non Standard Folder
sigmamedium