Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Command and Control/ T1001.003

T1001.003Protocol or Service Impersonation

T1001.003 — Protocol or Service Impersonation is a MITRE ATT&CK technique in the Command and Control tactic. Clankerusecase tracks 2 detection use cases covering it and 1 threat-intel article citing it.

Command and Control
View on the matrix → Filter Detection Library MITRE official spec ↗
2Use cases
1Articles
0Sub-techniques
1Tactic

Use cases covering this technique (2)

Splunk Protocol Impersonation Weak Encryption Configuration ESCU actions · hunting P [LLM] Exfil to lookalike Injective gRPC-web subdomain (@injectivelabs stealer C2) Bespoke c2 · alerting DSΣPDDCS

Articles citing this technique (1)