Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Exfiltration/ T1048.003

T1048.003Exfiltration Over Unencrypted Non-C2 Protocol

T1048.003 — Exfiltration Over Unencrypted Non-C2 Protocol is a MITRE ATT&CK technique in the Exfiltration tactic. Clankerusecase tracks 16 detection use cases covering it and 7 threat-intel articles citing it.

Exfiltration
View on the matrix → Filter Detection Library MITRE official spec ↗
16Use cases
7Articles
0Sub-techniques
1Tactic

Use cases covering this technique (16)

DNS tunneling / TXT-heavy domain queries Internal c2 · hunting DSP Cisco ASA - Device File Copy to Remote Location ESCU actions · hunting P Gsuite Outbound Email With Attachment To External Domain ESCU actions · hunting P Windows Rundll32 WebDAV Request ESCU actions · hunting P Windows Rundll32 WebDav With Network Connection ESCU actions · alerting P Cisco Secure Firewall - Potential Data Exfiltration ESCU actions · hunting P DNS Query Length With High Standard Deviation ESCU actions · hunting P Protocol or Port Mismatch ESCU actions · hunting P Multiple Archive Files Http Post Traffic ESCU actions · alerting P Plain HTTP POST Exfiltrated Data ESCU actions · alerting P Clients Connecting to Multiple DNS Servers ESCU actions · alerting P Detect DNS Data Exfiltration using pretrained model in DSDL ESCU actions · hunting P Detect Long DNS TXT Record Response ESCU actions · alerting P Detection of DNS Tunnels ESCU actions · alerting P [LLM] DNS tunneling exfiltration pattern to *.t.opentensor-cdn.com (hex chunk/index/total/session) Bespoke c2 · alerting DSΣPDD [LLM] SnakeStealer SMTP Credential Exfiltration to Public Webmail Relays from Non-Mail Client Bespoke actions · alerting DSΣPDDCS

Articles citing this technique (7)