MITRE ATT&CK technique
Non-Application Layer Protocol detection rulesT1095
Non-Application Layer Protocol (T1095) is a MITRE ATT&CK technique in the Command and Control tactic. This page lists the 3 community-maintained Sigma detection rules in the library mapped to T1095 and its sub-techniques. Each rule includes its detection logic, log source, false positives and original YAML. These rules mainly target windows, zeek.
Tactic
PUA - Netcat Suspicious Execution
highDetects execution of Netcat. Adversaries may use a non-application layer protocol for communication between host and C2 server or among infected hosts within a network
windows · process_creation
Netcat The Powershell Version
mediumAdversaries may use a non-application layer protocol for communication between host and C2 server or among infected hosts within a network
windows · ps_classic_start
Suspicious DNS Z Flag Bit Set
mediumThe DNS Z flag is bit within the DNS protocol header that is, per the IETF design, meant to be used reserved (unused). Although recently it has been used in DNSSec, the value being set to anything other than 0 should be rare. Otherwise if it is set to non 0 and DNSSec is being used, then excluding the legitimate domains is low effort and high reward. Determine if multiple of these files were accessed in a short period of time to further enhance the possibility of seeing if this was a one off or the possibility of larger sensitive file gathering. This Sigma query is designed to accompany the Corelight Threat Hunting Guide, which can be found here: https://www3.corelight.com/corelights-introductory-guide-to-threat-hunting-with-zeek-bro-logs'
zeek