Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Exfiltration/ T1048.003

T1048.003Exfiltration Over Unencrypted Non-C2 Protocol

T1048.003 — Exfiltration Over Unencrypted Non-C2 Protocol is a MITRE ATT&CK technique in the Exfiltration tactic. Clankerusecase tracks 18 detection use cases covering it and 8 threat-intel articles citing it.

Exfiltration
View on the matrix → Filter Detection Library MITRE official spec ↗
18Use cases
8Articles
0Sub-techniques
1Tactic

Use cases covering this technique (18)

DNS tunneling / TXT-heavy domain queries Internal c2 · hunting DSP Cisco ASA - Device File Copy to Remote Location ESCU actions · hunting P Gsuite Outbound Email With Attachment To External Domain ESCU actions · hunting P Windows Rundll32 WebDAV Request ESCU actions · hunting P Windows Rundll32 WebDav With Network Connection ESCU actions · alerting P Cisco Secure Firewall - Potential Data Exfiltration ESCU actions · hunting P DNS Query Length With High Standard Deviation ESCU actions · hunting P Protocol or Port Mismatch ESCU actions · hunting P Multiple Archive Files Http Post Traffic ESCU actions · alerting P Plain HTTP POST Exfiltrated Data ESCU actions · alerting P Clients Connecting to Multiple DNS Servers ESCU actions · alerting P Detect DNS Data Exfiltration using pretrained model in DSDL ESCU actions · hunting P Detect Long DNS TXT Record Response ESCU actions · alerting P Detection of DNS Tunnels ESCU actions · alerting P [LLM] OWAReaper C2 / exfiltration egress to TA488 CDN and DNS-tunnel domains Bespoke c2 · alerting DSΣPDDCS [LLM] DNS tunneling exfiltration pattern to *.t.opentensor-cdn.com (hex chunk/index/total/session) Bespoke c2 · alerting DSΣPDD [LLM] npm/node install hook exfiltrating /etc/passwd, kube config & krb5 ticket via wget --post-file Bespoke actions · alerting DSΣPDDCS [LLM] Outbound connection/DNS to npm exfil endpoint entfet95itcxpuu.m.pipedream.net Bespoke c2 · alerting DSΣPCS

Articles citing this technique (8)