{"id":"T1071.005","name":"Publish/Subscribe Protocols","url":"https://attack.mitre.org/techniques/T1071/005","tactics":["command-and-control"],"platforms":["macOS","Linux","Windows","Network Devices"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0002","stix_id":"x-mitre-detection-strategy--16495e17-03ec-4e11-ab80-f76ed6386329","name":"Behavioral Detection of Publish/Subscribe Protocol Misuse for C2","url":"https://attack.mitre.org/detectionstrategies/DET0002","analytics":[{"id":"AN0002","stix_id":"x-mitre-analytic--ee4e3e61-e138-498b-93bf-3a5f8fea691c","name":"Analytic 0002","description":"Detects non-standard processes (e.g., PowerShell, python.exe, rundll32.exe) making outbound connections using publish/subscribe protocols (e.g., MQTT, AMQP) over non-browser, encrypted channels, often beaconing to message brokers.","url":"https://attack.mitre.org/detectionstrategies/DET0002#AN0002","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=3, 22","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"wineventlog-sysmon"},{"name":"NSM:Flow","channel":"mqtt.log / xmpp.log (custom log feeds)","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"UnusualProcessList","description":"Detect suspicious processes initiating outbound pub/sub connections"},{"field":"TimeWindow","description":"Define beaconing interval used for temporal correlation"},{"field":"ProtocolPortList","description":"Custom MQTT/XMPP port use in non-standard ranges (e.g., 1883, 5222, 5672)"}],"live":true,"detection_strategies":["DET0002"],"techniques":["T1071.005"]},{"id":"AN0003","stix_id":"x-mitre-analytic--3ecc4ba2-bf4f-481c-b813-69c169c28c83","name":"Analytic 0003","description":"Detects CLI tools (e.g., mosquitto_pub, nc, python scripts) interacting with pub/sub brokers using unusual topic names, high-frequency publication rates, or obfuscated payloads to non-standard hosts.","url":"https://attack.mitre.org/detectionstrategies/DET0002#AN0003","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"},{"name":"NSM:Flow","channel":"mqtt.log or AMQP custom log","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"BrokerAllowList","description":"Known-good brokers used by approved apps and daemons"},{"field":"TopicAnomalyScore","description":"Payload length, entropy, or topic name patterns"}],"live":true,"detection_strategies":["DET0002"],"techniques":["T1071.005"]},{"id":"AN0004","stix_id":"x-mitre-analytic--131d3f89-e10d-4ac9-a9d0-fcb4e8e8760a","name":"Analytic 0004","description":"Detects osascript, curl, or custom binaries interacting with XMPP/MQTT brokers in unapproved destinations with encrypted payloads or frequent POST-like requests to broker URIs.","url":"https://attack.mitre.org/detectionstrategies/DET0002#AN0004","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"log stream 'eventMessage contains pubsub or broker'","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"},{"name":"macos:osquery","channel":"socket_events","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"macos-osquery"}],"mutable_elements":[{"field":"AppContextFilter","description":"Applications not known to use pub/sub protocols"},{"field":"URIPathRegex","description":"Custom path patterns to message brokers over HTTPS"}],"live":true,"detection_strategies":["DET0002"],"techniques":["T1071.005"]},{"id":"AN0005","stix_id":"x-mitre-analytic--748f457a-5dfa-431b-b5a0-3d5e1d56ebbb","name":"Analytic 0005","description":"Detects pub/sub traffic over unusual ports, high-frequency topic publications, and connections to known-bad or dynamic broker endpoints outside allowlisted infrastructure.","url":"https://attack.mitre.org/detectionstrategies/DET0002#AN0005","platforms":["Network Devices"],"log_source_references":[{"name":"NSM:Flow","channel":"mqtt.log, xmpp.log, amqp.log","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"BrokerReputationList","description":"Dynamic blocklist or threat intel feed for C2 brokers"},{"field":"PayloadLengthThreshold","description":"Exfil-style long topic messages vs telemetry-style short messages"}],"live":true,"detection_strategies":["DET0002"],"techniques":["T1071.005"]}],"live":true,"version":"1.0","techniques":["T1071.005"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}