Detection Playbook: Exfiltration Over C2 Channel (T1041)
Exfiltration Over C2 Channel (T1041) describes the technique where an adversary reuses an already-established command-and-control communication channel to sm…
Threat Intelligence for Every Defender
Daily MITRE ATT&CK-based detection playbooks covering common adversary techniques. Each playbook includes SIEM-agnostic detection logic and investigation and response guidance.
Exfiltration Over C2 Channel (T1041) describes the technique where an adversary reuses an already-established command-and-control communication channel to sm…
Local Data Staging (T1074.001) is the practice of collecting and consolidating files of interest — credentials, documents, database dumps, configuration file…
Archive via Utility (T1560.001) describes adversaries using compression and archiving tools — such as tar , zip , 7-Zip , WinRAR , makecab , or certutil — to…
Data Destruction (T1485) is an impact-phase technique where adversaries deliberately overwrite, corrupt, or permanently delete files and data to make recover…
External Remote Services (T1133) describes adversaries abusing legitimate remote access mechanisms — VPNs, Citrix, RDP gateways, SSH, VNC, exposed APIs, and …
Malicious File (T1204.002) describes an attacker tricking a user into opening a weaponized file — such as a macro-enabled Office document, a disguised execut…
T1059.007 covers adversary abuse of JavaScript and its runtime variants — including JScript on Windows, Node.js across platforms, and JavaScript for Automati…
Match Legitimate Resource Name or Location (T1036.005) is a masquerading technique where adversaries rename malicious executables, scripts, or other resource…
Modify Registry (T1112) describes adversary interactions with the Windows Registry to achieve defense evasion, persistence, or execution. Attackers use regis…
File and Directory Discovery (T1083) refers to adversaries actively enumerating the file system — listing directories, searching for specific file types, and…