MITRE ATT&CK technique
Encrypted Channel detection rulesT1573
Encrypted Channel (T1573) is a MITRE ATT&CK technique in the Command and Control tactic. This page lists the 6 community-maintained Sigma detection rules in the library mapped to T1573 and its sub-techniques. Each rule includes its detection logic, log source, false positives and original YAML. These rules mainly target windows, m365.
Tactic
Kalambur Backdoor Curl TOR SOCKS Proxy Execution
highDetects the execution of the "curl.exe" command, referencing "SOCKS" and ".onion" domains, which could be indicative of Kalambur backdoor activity.
windows · process_creation
Potential Pikabot C2 Activity
highDetects the execution of rundll32 that leads to an external network connection. The malware Pikabot has been seen to use this technique to initiate C2-communication through hard-coded Windows binaries.
windows · network_connection
Activity from Anonymous IP Addresses
mediumDetects when a Microsoft Cloud App Security reported when users were active from an IP address that has been identified as an anonymous proxy IP address.
m365
Activity from Infrequent Country
mediumDetects when a Microsoft Cloud App Security reported when an activity occurs from a location that wasn't recently or never visited by any user in the organization.
m365
Activity from Suspicious IP Addresses
mediumDetects when a Microsoft Cloud App Security reported users were active from an IP address identified as risky by Microsoft Threat Intelligence. These IP addresses are involved in malicious activities, such as Botnet C&C, and may indicate compromised account.
m365
Suspicious SSL Connection
lowAdversaries may employ a known encryption algorithm to conceal command and control traffic rather than relying on any inherent protections provided by a communication protocol.
windows · ps_script