{"id":"T1041","name":"Exfiltration Over C2 Channel","url":"https://attack.mitre.org/techniques/T1041","tactics":["exfiltration"],"platforms":["ESXi","Linux","macOS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0348","stix_id":"x-mitre-detection-strategy--beb3a98c-f1a4-434a-81e7-29d178b14db2","name":"Detection Strategy for Exfiltration Over C2 Channel","url":"https://attack.mitre.org/detectionstrategies/DET0348","analytics":[{"id":"AN0988","stix_id":"x-mitre-analytic--28c16139-9ce1-4dd7-b26a-e257f37e246c","name":"Analytic 0988","description":"Identifies suspicious outbound traffic volume mismatches from processes that typically do not generate network activity, particularly over C2 protocols like HTTPS, DNS, or custom TCP/UDP ports, following file or data access.","url":"https://attack.mitre.org/detectionstrategies/DET0348#AN0988","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=3, 22","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"wineventlog-sysmon"},{"name":"NSM:Flow","channel":"Flow/PCAP analysis for outbound payloads","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"nsm-flow"},{"name":"WinEventLog:Security","channel":"EventCode=4663, 4670, 4656","data_component":"DC0055","data_component_name":"File Access","log_source_slug":"wineventlog-security"}],"mutable_elements":[{"field":"DataVolumeThreshold","description":"Set threshold for outbound transfer size exceeding typical C2 traffic (e.g., >1MB in <5min)."},{"field":"KnownBenignProcesses","description":"List of approved processes that may exhibit high outbound traffic (e.g., updates)."}],"live":true,"detection_strategies":["DET0348"],"techniques":["T1041"]},{"id":"AN0989","stix_id":"x-mitre-analytic--6914dd62-46a6-4de4-9c0b-afe1cb5b075d","name":"Analytic 0989","description":"Monitors for processes reading sensitive files then immediately initiating unusual outbound connections or bulk transfer sessions over persistent sockets, particularly with encrypted or binary payloads.","url":"https://attack.mitre.org/detectionstrategies/DET0348#AN0989","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"},{"name":"auditd:SYSCALL","channel":"connect","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"auditd-syscall"},{"name":"NSM:Flow","channel":"conn.log + files.log + ssl.log","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"nsm-flow"},{"name":"NSM:Flow","channel":"session stats with bytes_out > bytes_in","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"OutboundEntropyScore","description":"Threshold for high-entropy payloads indicative of encoded or encrypted exfil data."},{"field":"ConnectionDuration","description":"Defines length of time over which transfer size must be aggregated to trigger detection."}],"live":true,"detection_strategies":["DET0348"],"techniques":["T1041"]},{"id":"AN0990","stix_id":"x-mitre-analytic--deb57305-6324-404d-a9d0-00aa0c285920","name":"Analytic 0990","description":"Detects unauthorized applications or scripts accessing sensitive data followed by establishing encrypted outbound communication to rare external destinations or with abnormal byte ratios.","url":"https://attack.mitre.org/detectionstrategies/DET0348#AN0990","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"eventMessage = 'open', 'sendto', 'connect'","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"macos-unifiedlog"},{"name":"macos:osquery","channel":"socket_events","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"macos-osquery"},{"name":"macos:osquery","channel":"process_events","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-osquery"}],"mutable_elements":[{"field":"ParentProcessAncestry","description":"Enables defenders to tune legitimate vs. suspicious lineage (e.g., launchd → curl is uncommon)."},{"field":"ProtocolList","description":"Focus detection on unusual protocols (e.g., IRC, FTP, DNS over HTTPS)."}],"live":true,"detection_strategies":["DET0348"],"techniques":["T1041"]},{"id":"AN0991","stix_id":"x-mitre-analytic--f8998263-e55f-428f-b8d0-46d9e31277d2","name":"Analytic 0991","description":"Detects VMs sending outbound traffic through non-standard services or to unknown destinations. Exfiltration over reverse shells tunneled via VMkernel or custom payloads routed via hostd/vpxa.","url":"https://attack.mitre.org/detectionstrategies/DET0348#AN0991","platforms":["ESXi"],"log_source_references":[{"name":"esxi:vpxa","channel":"connection attempts and data transmission logs","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"esxi-vpxa"},{"name":"esxi:vmkernel","channel":"network stack module logs","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"esxi-vmkernel"},{"name":"esxi:syslog","channel":"guest OS outbound transfer logs","data_component":"DC0055","data_component_name":"File Access","log_source_slug":"esxi-syslog"}],"mutable_elements":[{"field":"GuestOSAllowList","description":"Limit detection to sensitive or externally-exposed VMs handling confidential data."},{"field":"TransferSizeThresholdMB","description":"Minimum outbound transfer size before flagging anomalous C2-based exfiltration."},{"field":"ProtocolAllowList","description":"Define expected protocols for outbound data (e.g., disallow FTP/SCP over high ports)."}],"live":true,"detection_strategies":["DET0348"],"techniques":["T1041"]}],"live":true,"version":"1.0","techniques":["T1041"]}],"sigma_rules":[{"id":"07837ab9-60e1-481f-a74d-c31fb496a94c","title":"Network Communication Initiated To Portmap.IO Domain","author":"Florian Roth (Nextron Systems)","status":"test","level":"medium","date":"2024-05-31","modified":null,"description":"Detects an executable accessing the portmap.io domain, which could be a sign of forbidden C2 traffic or data exfiltration by malicious actors","references":["https://portmap.io/","https://github.com/rapid7/metasploit-framework/issues/11337","https://pro.twitter.com/JaromirHorejsi/status/1795001037746761892/photo/2"],"logsource":{"product":"windows","category":"network_connection"},"tags":["attack.t1041","attack.command-and-control","attack.t1090.002","attack.exfiltration"],"path":"rules/windows/network_connection/net_connection_win_domain_portmap.yml","techniques":["T1041","T1090.002"],"cves":[]},{"id":"881834a4-6659-4773-821e-1c151789d873","title":"Equation Group C2 Communication","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2017-04-15","modified":"2021-11-27","description":"Detects communication to C2 servers mentioned in the operational notes of the ShadowBroker leak of EquationGroup C2 tools","references":["https://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation","https://medium.com/@msuiche/the-nsa-compromised-swift-network-50ec3000b195"],"logsource":{"category":"firewall"},"tags":["attack.exfiltration","attack.command-and-control","attack.g0020","attack.t1041","detection.emerging-threats"],"path":"rules-emerging-threats/2017/TA/Equation-Group/net_firewall_apt_equationgroup_c2.yml","techniques":["T1041"],"cves":[]},{"id":"b4e6b016-a2ac-4759-ad85-8000b300d61e","title":"OpenCanary - TFTP Request","author":"Security Onion Solutions","status":"test","level":"high","date":"2024-03-08","modified":null,"description":"Detects instances where a TFTP service on an OpenCanary node has had a request.","references":["https://opencanary.readthedocs.io/en/latest/starting/configuration.html#services-configuration","https://github.com/thinkst/opencanary/blob/a0896adfcaf0328cfd5829fe10d2878c7445138e/opencanary/logger.py#L52"],"logsource":{"product":"opencanary","category":"application"},"tags":["attack.exfiltration","attack.t1041"],"path":"rules/application/opencanary/opencanary_tftp_request.yml","techniques":["T1041"],"cves":[]},{"id":"c75309a3-59f8-4a8d-9c2c-4c927ad50555","title":"Tunneling Tool Execution","author":"Daniil Yugoslavskiy, oscd.community","status":"test","level":"medium","date":"2019-10-24","modified":"2024-01-18","description":"Detects the execution of well known tools that can be abused for data exfiltration and tunneling.","references":["https://www.microsoft.com/en-us/security/blog/2022/07/26/malicious-iis-extensions-quietly-open-persistent-backdoors-into-servers/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.exfiltration","attack.command-and-control","attack.t1041","attack.t1572","attack.t1071.001","detection.threat-hunting"],"path":"rules-threat-hunting/windows/process_creation/proc_creation_win_susp_exfil_and_tunneling_tool_execution.yml","techniques":["T1041","T1572","T1071.001"],"cves":[]},{"id":"efd2eb09-b72e-4a61-8dc7-b1382a1e8983","title":"Shai-Hulud NPM Package Malicious Exfiltration via Curl","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"high","date":"2025-09-24","modified":null,"description":"Detects potential Shai Hulud NPM package attack attempting to exfiltrate data via curl to external webhook sites.","references":["https://www.getsafety.com/blog-posts/shai-hulud-npm-attack"],"logsource":{"product":"linux","category":"process_creation"},"tags":["attack.exfiltration","attack.t1041","attack.collection","attack.t1005","detection.emerging-threats"],"path":"rules-emerging-threats/2025/Malware/Shai-Hulud/proc_creation_lnx_mal_shai_hululd_exfiltration.yml","techniques":["T1041","T1005"],"cves":[]}],"kev_cves":[{"cveID":"CVE-2025-33053","state":"mapped","mapping_types":["secondary_impact"]},{"cveID":"CVE-2024-27443","state":"mapped","mapping_types":["secondary_impact"]},{"cveID":"CVE-2025-32756","state":"mapped","mapping_types":["secondary_impact"]},{"cveID":"CVE-2024-55550","state":"mapped","mapping_types":["secondary_impact"]},{"cveID":"CVE-2024-4577","state":"mapped","mapping_types":["secondary_impact"]},{"cveID":"CVE-2023-5631","state":"mapped","mapping_types":["secondary_impact"]},{"cveID":"CVE-2023-38831","state":"mapped","mapping_types":["secondary_impact"]},{"cveID":"CVE-2023-2868","state":"mapped","mapping_types":["secondary_impact"]},{"cveID":"CVE-2023-1389","state":"mapped","mapping_types":["secondary_impact"]},{"cveID":"CVE-2018-4878","state":"mapped","mapping_types":["secondary_impact"]},{"cveID":"CVE-2019-0604","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2019-18935","state":"mapped","mapping_types":["primary_impact"]}],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}