MITRE ATT&CK technique
Application Layer Protocol detection rulesT1071
Application Layer Protocol (T1071) is a MITRE ATT&CK technique in the Command and Control tactic. This page lists the 65 community-maintained Sigma detection rules in the library mapped to T1071 and its sub-techniques. Each rule includes its detection logic, log source, false positives and original YAML. These rules mainly target windows, zeek, linux.
Tactic
Cobalt Strike DNS Beaconing
criticalDetects suspicious DNS queries known from Cobalt Strike beacons
dns
HackTool - BabyShark Agent Default URL Pattern
criticalDetects Baby Shark C2 Framework default communication patterns
proxy
OilRig APT Activity
criticalDetects OilRig activity as reported by Nyotron in their March 2018 report
windows · process_creation
OilRig APT Registry Persistence
criticalDetects OilRig registry persistence as reported by Nyotron in their March 2018 report
windows · registry_event
OilRig APT Schedule Task Persistence - Security
criticalDetects OilRig schedule task persistence as reported by Nyotron in their March 2018 report
windows
OilRig APT Schedule Task Persistence - System
criticalDetects OilRig schedule task persistence as reported by Nyotron in their March 2018 report
windows
PwnDrp Access
criticalDetects downloads from PwnDrp web servers developed for red team testing and most likely also used for criminal activity
proxy
Silence.EDA Detection
criticalDetects Silence EmpireDNSAgent as described in the Group-IP report
windows · ps_script
Suspicious Cobalt Strike DNS Beaconing - DNS Client
criticalDetects a program that invoked suspicious DNS queries known from Cobalt Strike beacons
windows
Suspicious Cobalt Strike DNS Beaconing - Sysmon
criticalDetects a program that invoked suspicious DNS queries known from Cobalt Strike beacons
windows · dns_query
Ursnif Malware C2 URL Pattern
criticalDetects Ursnif C2 traffic.
proxy
APT User Agent
highDetects suspicious user agent strings used in APT malware in proxy logs
proxy
APT40 Dropbox Tool User Agent
highDetects suspicious user agent string of APT40 Dropbox tool
proxy
Axios NPM Compromise Malicious C2 Domain DNS Query
highDetects DNS queries for the malicious C2 domain associated with the plain-crypto-js/Axios npm package supply chain compromise. On March 30, 2026, malicious versions (1.14.1, 0.30.4) were published to npm, injecting a dependency (plain-crypto-js@4.2.1) that executed a postinstall script as a cross-platform RAT dropper. This detection detects endpoints attempting to resolve the attacker's C2 domain (sfrclak.com) used for command and control communication.
dns
Bitsadmin to Uncommon IP Server Address
highDetects Bitsadmin connections to IP addresses instead of FQDN names
proxy
Bitsadmin to Uncommon TLD
highDetects Bitsadmin connections to domains with uncommon TLDs
proxy
Chafer Malware URL Pattern
highDetects HTTP request used by Chafer malware to receive data from its C2.
proxy
ComRAT Network Communication
highDetects Turla ComRAT network communication.
proxy
Crypto Miner User Agent
highDetects suspicious user agent strings used by crypto miners in proxy logs
proxy
DNS Exfiltration and Tunneling Tools Execution
highWell-known DNS Exfiltration tools execution
windows · process_creation
DNS Query by Finger Utility
highDetects DNS queries made by the finger utility, which can be abused by threat actors to retrieve remote commands for execution on Windows devices. In one ClickFix malware campaign, adversaries leveraged the finger protocol to fetch commands from a remote server. Since the finger utility is not commonly used in modern Windows environments, its presence already raises suspicion. Investigating such DNS queries can also help identify potential malicious infrastructure used by threat actors for command and control (C2) communication.
windows · dns_query
DNS Query To Katz Stealer Domains
highDetects DNS queries to domains associated with Katz Stealer malware. Katz Stealer is a malware variant that is known to be used for stealing sensitive information from compromised systems. In Enterprise environments, DNS queries to these domains may indicate potential malicious activity or compromise.
windows · dns_query
DNS Query To Katz Stealer Domains - Network
highDetects DNS queries to domains associated with Katz Stealer malware. Katz Stealer is a malware variant that is known to be used for stealing sensitive information from compromised systems. In Enterprise environments, DNS queries to these domains may indicate potential malicious activity or compromise.
dns
DNS TXT Answer with Possible Execution Strings
highDetects strings used in command execution in DNS TXT Answer
dns
Exploit Framework User Agent
highDetects suspicious user agent strings used by exploit / pentest frameworks like Metasploit in proxy logs
proxy
GALLIUM Artefacts - Builtin
highDetects artefacts associated with activity group GALLIUM - Microsoft Threat Intelligence Center indicators released in December 2019.
windows
GALLIUM IOCs
highDetects artifacts associated with GALLIUM cyber espionage group as reported by Microsoft Threat Intelligence Center in the December 2019 report.
windows · process_creation
HackTool - CobaltStrike Malleable Profile Patterns - Proxy
highDetects cobalt strike malleable profiles patterns (URI, User-Agents, Methods).
proxy
HackTool - Empire UserAgent URI Combo
highDetects user agent and URI paths used by empire agents
proxy
HackTool - SILENTTRINITY Stager DLL Load
highDetects SILENTTRINITY stager dll loading activity
windows · image_load
HackTool - SILENTTRINITY Stager Execution
highDetects SILENTTRINITY stager use via PE metadata
windows · process_creation
Kalambur Backdoor Curl TOR SOCKS Proxy Execution
highDetects the execution of the "curl.exe" command, referencing "SOCKS" and ".onion" domains, which could be indicative of Kalambur backdoor activity.
windows · process_creation
Katz Stealer Suspicious User-Agent
highDetects network connections with a suspicious user-agent string containing "katz-ontop", which may indicate Katz Stealer activity.
zeek
Malware User Agent
highDetects suspicious user agent strings used by malware in proxy logs
proxy
Network Connection Initiated via Finger.EXE
highDetects network connections via finger.exe, which can be abused by threat actors to retrieve remote commands for execution on Windows devices. In one ClickFix malware campaign, adversaries leveraged the finger protocol to fetch commands from a remote server. Since the finger utility is not commonly used in modern Windows environments, its presence already raises suspicion. Investigating such network connections can also help identify potential malicious infrastructure used by threat actors
windows · network_connection
Outbound Network Connection Initiated By Microsoft Dialer
highDetects outbound network connection initiated by Microsoft Dialer. The Microsoft Dialer, also known as Phone Dialer, is a built-in utility application included in various versions of the Microsoft Windows operating system. Its primary function is to provide users with a graphical interface for managing phone calls via a modem or a phone line connected to the computer. This is an outdated process in the current conext of it's usage and is a common target for info stealers for process injection, and is used to make C2 connections, common example is "Rhadamanthys"
windows · network_connection
Raw Paste Service Access
highDetects direct access to raw pastes in different paste services often used by malware in their second stages to download malicious code in encrypted or encoded form
proxy
Renamed Visual Studio Code Tunnel Execution
highDetects renamed Visual Studio Code tunnel execution. Attackers can abuse this functionality to establish a C2 channel
windows · process_creation
Suspicious User Agent
highDetects suspicious malformed user agent strings in proxy logs
proxy
Ursnif Malware Download URL Pattern
highDetects download of Ursnif malware done by dropper documents.
proxy
Wannacry Killswitch Domain
highDetects wannacry killswitch domain dns queries
dns
Windows WebDAV User Agent
highDetects WebDav DownloadCradle
proxy
Change User Agents with WebRequest
mediumAdversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.
windows · ps_script
Cloudflared Tunnels Related DNS Requests
mediumDetects DNS requests to Cloudflared tunnels domains. Attackers can abuse that feature to establish a reverse shell or persistence on a machine.
windows · dns_query
Curl.EXE Execution With Custom UserAgent
mediumDetects execution of curl.exe with custom useragent options
windows · process_creation
DNS Query To Common Malware Hosting and Shortener Services
mediumDetects DNS queries to domains commonly used by threat actors to host malware payloads or redirect through URL shorteners. These include platforms like Cloudflare Workers, TryCloudflare, InfinityFree, and URL shorteners such as tinyurl and lihi.cc. Such DNS activity can indicate potential delivery or command-and-control communication attempts.
windows · dns_query
DNS Query To Devtunnels Domain
mediumDetects DNS query requests to Devtunnels domains. Attackers can abuse that feature to establish a reverse shell or persistence on a machine.
windows · dns_query
DNS Query To Visual Studio Code Tunnels Domain
mediumDetects DNS query requests to Visual Studio Code tunnel domains. Attackers can abuse that feature to establish a reverse shell or persistence on a machine.
windows · dns_query
Github Self-Hosted Runner Execution
mediumDetects GitHub self-hosted runners executing workflows on local infrastructure that could be abused for persistence and code execution. Shai-Hulud is an npm supply chain worm targeting CI/CD environments. It installs runners on compromised systems to maintain access after credential theft, leveraging their access to secrets and internal networks.
windows · process_creation
HTTP Request With Empty User Agent
mediumDetects a potentially suspicious empty user agent strings in proxy log. Could potentially indicate an uncommon request method.
proxy
Low Reputation Effective Top-Level Domain (eTLD)
mediumDetects DNS queries to domains within known low reputation eTLDs. This rule uses AlphaSOC's threat intelligence data and is updated on a monthly basis.
dns
Potential Base64 Encoded User-Agent
mediumDetects User Agent strings that end with an equal sign, which can be a sign of base64 encoding.
proxy
Potentially Suspicious Rundll32.EXE Execution of UDL File
mediumDetects the execution of rundll32.exe with the oledb32.dll library to open a UDL file. Threat actors can abuse this technique as a phishing vector to capture authentication credentials or other sensitive data.
windows · process_creation
Suspicious Base64 Encoded User-Agent
mediumDetects suspicious encoded User-Agent strings, as seen used by some malware.
proxy
Suspicious Curl Change User Agents - Linux
mediumDetects a suspicious curl process start on linux with set useragent options
linux · process_creation
Suspicious DNS Query with B64 Encoded String
mediumDetects suspicious DNS queries using base64 encoding
dns
Suspicious Installer Package Child Process
mediumDetects the execution of suspicious child processes from macOS installer package parent process. This includes osascript, JXA, curl and wget amongst other interpreters
macos · process_creation
TanStack Supply-Chain Attack DNS Indicators
mediumDetects DNS queries to attacker-controlled infrastructure used by the Mini Shai-Hulud campaign targeting TanStack npm packages along with other packages such as mistralai, uipath and so on. The domain git-tanstack.com (registered May 9, 2026) hosted secondary payloads including transformers.pyz. The filev2.getsession.org endpoint was used for credential exfiltration via the Session protocol.
windows · dns_query
Telegram API Access
mediumDetects suspicious requests to Telegram API without the usual Telegram User-Agent
proxy
Tunneling Tool Execution
mediumDetects the execution of well known tools that can be abused for data exfiltration and tunneling.
windows · process_creation
Visual Studio Code Tunnel Execution
mediumDetects Visual Studio Code tunnel execution. Attackers can abuse this functionality to establish a C2 channel
windows · process_creation
Visual Studio Code Tunnel Service Installation
mediumDetects the installation of VsCode tunnel (code-tunnel) as a service.
windows · process_creation
Visual Studio Code Tunnel Shell Execution
mediumDetects the execution of a shell (powershell, bash, wsl...) via Visual Studio Code tunnel. Attackers can abuse this functionality to establish a C2 channel and execute arbitrary commands on the system.
windows · process_creation
Windows PowerShell User Agent
mediumDetects Windows PowerShell Web Access
proxy
DNS Query Request By QuickAssist.EXE
lowDetects DNS queries initiated by "QuickAssist.exe" to Microsoft Quick Assist primary endpoint that is used to establish a session.
windows · dns_query