kevmap

TechniquesT1071.001 › AN0079

AN0079 Analytic 0079

Network Devices · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Detects Web protocol misuse such as encoded HTTP headers, WebSocket upgrade requests with abnormal payloads, or TLS handshake anomalies suggesting embedded C2 channels.</p>
Detects
T1071.001 Web Protocols
Part of
DET0027 Detection of Web Protocol-Based C2 Over HTTP, HTTPS, or WebSockets

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
NSM:Flowhttp.log, ssl.log, websocket.logDC0085 Network Traffic Content

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
HeaderEncodingPatternBase64, hex, or UTF-16 encoding in URI, cookie, or host
TLSFingerprintMismatchJA3 hash deviation from known clients

KEV CVEs whose mapped technique this analytic detects

CVEVendor / productState
CVE-2009-4324Adobe Acrobat and ReaderMapped
CVE-2015-3113Adobe Flash PlayerMapped
CVE-2015-5119Adobe Flash PlayerMapped
CVE-2021-35394Realtek Jungle Software Development Kit (SDK)Mapped
CVE-2021-40449Microsoft WindowsMapped
CVE-2022-42475Fortinet FortiOSMapped
CVE-2023-26360Adobe ColdFusionMapped
CVE-2023-38035Ivanti SentryMapped
CVE-2024-4577PHP Group PHPMapped
CVE-2024-4978Justice AV Solutions Viewer Mapped