Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Command and Control/ T1095

T1095Non-Application Layer Protocol

T1095 — Non-Application Layer Protocol is a MITRE ATT&CK technique in the Command and Control tactic. Clankerusecase tracks 8 detection use cases covering it and 5 threat-intel articles citing it.

Command and Control
View on the matrix → Filter Detection Library MITRE official spec ↗
8Use cases
5Articles
0Sub-techniques
1Tactic

Use cases covering this technique (8)

Linux Proxy Socks Curl ESCU actions · alerting P Detect Large ICMP Traffic ESCU actions · alerting P Detect Large Outbound ICMP Packets ESCU actions · alerting P [LLM] TuxBot/Akiru IoT botnet C2 connection to known infrastructure Bespoke c2 · hunting DSΣPCS [LLM] SprySOCKS (FishMonger/I-SOON) C2 beacon to hardcoded Vultr IPs 207.148.78.36 / 207.148.75.122 Bespoke c2 · hunting DSΣPDDCS [LLM] Beaconing to GopherWhisper C2 IP 43.231.113.50 (incl. SSLORDoor raw TLS/443) Bespoke c2 · alerting DSΣPDDCS [LLM] Outbound TCP beacon to BlokTrooper Socket.IO C2 195.201.104.53:6931/6936/6939 Bespoke c2 · alerting DSΣPDDCS [LLM] Interactive shell process initiating outbound network connection (reverse-shell C2) Bespoke c2 · hunting DSPCS

Articles citing this technique (5)