Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Command and Control/ T1071

T1071Application Layer Protocol

T1071 — Application Layer Protocol is a MITRE ATT&CK technique in the Command and Control tactic. Clankerusecase tracks 13 detection use cases covering it and 423 threat-intel articles citing it.

Command and Control
View on the matrix → Filter Detection Library MITRE official spec ↗
13Use cases
423Articles
5Sub-techniques
1Tactic

Sub-techniques (5)

Use cases covering this technique (13)

Network connections to article IPs / domains Internal c2 · alerting DSΣP [WEEKLY] Auth-Bypass on Public-Facing Service → Post-Exploit Action on Same Host (≤10 min) Internal exploit · alerting DSPDD Windows App Layer Protocol Qakbot NamedPipe ESCU actions · hunting P Windows App Layer Protocol Wermgr Connect To NamedPipe ESCU actions · hunting P Windows Application Layer Protocol RMS Radmin Tool Namedpipe ESCU actions · alerting P Cisco Secure Firewall - High Priority Intrusion Classification ESCU actions · alerting P Cisco Secure Firewall - High Volume of Intrusion Events Per Host ESCU actions · hunting P [LLM] Outbound beacon/callback from internal host to VeloCloud Orchestrator attacker IPs (CVE-2026-16812) Bespoke c2 · alerting DSΣPDDCS [LLM] Outbound reverse-shell egress from GitLab Ruby/Puma worker as git — Oj RCE connect-back Bespoke c2 · hunting DSPCS [LLM] redis-server initiates unexpected outbound / lateral connections (post-RCE egress) Bespoke actions · hunting DSPCS [LLM] SprySOCKS (FishMonger/I-SOON) C2 beacon to hardcoded Vultr IPs 207.148.78.36 / 207.148.75.122 Bespoke c2 · hunting DSΣPDDCS [LLM] Outbound C2 to sfrclak.com / 142.11.206.73:8000 (Axios npm RAT beacon) Bespoke c2 · alerting DSΣPDDCS [LLM] CircleCI breach C2 egress to potrax[.]com and 8 hardcoded attacker IPs Bespoke c2 · hunting DSΣPCSCW

Articles citing this technique (423)