kevmap

TechniquesT1071.001 › AN0075

AN0075 Analytic 0075

Windows · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Detects unexpected or high-volume HTTP/S/WebSocket communication from suspicious processes (e.g., PowerShell, rundll32) using uncommon user agents or mimicking browser traffic to unusual domains or IPs.</p>
Detects
T1071.001 Web Protocols
Part of
DET0027 Detection of Web Protocol-Based C2 Over HTTP, HTTPS, or WebSockets

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
NSM:Flowhttp.log, ssl.logDC0085 Network Traffic Content
WinEventLog:SysmonEventCode=3, 22DC0082 Network Connection Creation

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
ProcessNameExclusionsFilter out legitimate browser/network utilities
UserAgentAnomaliesDetect non-browser user-agents or spoofed headers
OutboundByteRatioThresholdFlag when outbound > inbound volume by 90%+

KEV CVEs whose mapped technique this analytic detects

CVEVendor / productState
CVE-2009-4324Adobe Acrobat and ReaderMapped
CVE-2015-3113Adobe Flash PlayerMapped
CVE-2015-5119Adobe Flash PlayerMapped
CVE-2021-35394Realtek Jungle Software Development Kit (SDK)Mapped
CVE-2021-40449Microsoft WindowsMapped
CVE-2022-42475Fortinet FortiOSMapped
CVE-2023-26360Adobe ColdFusionMapped
CVE-2023-38035Ivanti SentryMapped
CVE-2024-4577PHP Group PHPMapped
CVE-2024-4978Justice AV Solutions Viewer Mapped