MITRE ATT&CK technique
Exfiltration Over C2 Channel detection rulesT1041
Exfiltration Over C2 Channel (T1041) is a MITRE ATT&CK technique in the Exfiltration tactic. This page lists the 5 community-maintained Sigma detection rules in the library mapped to T1041 and its sub-techniques. Each rule includes its detection logic, log source, false positives and original YAML. These rules mainly target windows, opencanary, linux.
Top products
Tactic
Equation Group C2 Communication
highDetects communication to C2 servers mentioned in the operational notes of the ShadowBroker leak of EquationGroup C2 tools
firewall
OpenCanary - TFTP Request
highDetects instances where a TFTP service on an OpenCanary node has had a request.
opencanary · application
Shai-Hulud NPM Package Malicious Exfiltration via Curl
highDetects potential Shai Hulud NPM package attack attempting to exfiltrate data via curl to external webhook sites.
linux · process_creation
Network Communication Initiated To Portmap.IO Domain
mediumDetects an executable accessing the portmap.io domain, which could be a sign of forbidden C2 traffic or data exfiltration by malicious actors
windows · network_connection
Tunneling Tool Execution
mediumDetects the execution of well known tools that can be abused for data exfiltration and tunneling.
windows · process_creation