Sigma Rule Library

MITRE ATT&CK technique

Non-Application Layer Protocol detection rulesT1095

Non-Application Layer Protocol (T1095) is a MITRE ATT&CK technique in the Command and Control tactic. This page lists the 3 community-maintained Sigma detection rules in the library mapped to T1095 and its sub-techniques. Each rule includes its detection logic, log source, false positives and original YAML. These rules mainly target windows, zeek.

Top products

Tactic