{"id":"T1090.004","name":"Domain Fronting","url":"https://attack.mitre.org/techniques/T1090/004","tactics":["command-and-control"],"platforms":["Linux","macOS","Windows","ESXi"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0196","stix_id":"x-mitre-detection-strategy--92203cb2-b7bd-4bc3-ab6f-9859a9856efc","name":"Domain Fronting Behavior via Mismatched TLS SNI and HTTP Host Headers","url":"https://attack.mitre.org/detectionstrategies/DET0196","analytics":[{"id":"AN0564","stix_id":"x-mitre-analytic--e5cb92b6-75b0-4eed-aa1e-4ea529f50fbb","name":"Analytic 0564","description":"Suspicious outbound HTTPS connections where the TLS Server Name Indication (SNI) does not match the HTTP Host header, indicating potential use of domain fronting to mask C2 traffic via CDNs.","url":"https://attack.mitre.org/detectionstrategies/DET0196#AN0564","platforms":["Windows"],"log_source_references":[{"name":"NSM:Connections","channel":"TLS handshake + HTTP headers","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"nsm-connections"},{"name":"WinEventLog:Sysmon","channel":"EventCode=3, 22","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"SNIHostMismatch","description":"Define acceptable mismatch ratio between SNI and HTTP Host fields based on legitimate domain usage patterns."},{"field":"CDNAllowList","description":"Whitelist of known safe CDN front-end domains (e.g., `cdn.company.com`)."},{"field":"ProcessInitiator","description":"Filter for suspicious initiators of domain fronting, e.g., scripting engines, lolbins, unknown binaries."}],"live":true,"detection_strategies":["DET0196"],"techniques":["T1090.004"]},{"id":"AN0565","stix_id":"x-mitre-analytic--e031d1a5-92a9-46df-9467-d6899d48f57b","name":"Analytic 0565","description":"Applications such as `curl`, `wget`, or custom binaries initiate HTTPS connections where the TLS SNI is mismatched or absent while HTTP Host targets CDN-available C2 endpoints.","url":"https://attack.mitre.org/detectionstrategies/DET0196#AN0565","platforms":["Linux"],"log_source_references":[{"name":"NSM:Flow","channel":"ssl.log + http.log","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"nsm-flow"},{"name":"auditd:SYSCALL","channel":"execve","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"}],"mutable_elements":[{"field":"SNIFieldAbsent","description":"Detect TLS sessions where SNI is empty—'domainless' fronting."},{"field":"AllowedTools","description":"Environmental tuning for known binaries using alternate SNI for testing (e.g., API tests)."},{"field":"ProcessContext","description":"Enrich command-line arguments or parent-child lineage to detect abuse."}],"live":true,"detection_strategies":["DET0196"],"techniques":["T1090.004"]},{"id":"AN0566","stix_id":"x-mitre-analytic--b4cf91ba-a22b-49b4-978e-32c3e1301c74","name":"Analytic 0566","description":"Unsigned or user-space apps initiate TLS connections with one hostname and HTTP headers requesting a different domain, commonly abused in CDN-resident domain fronting techniques.","url":"https://attack.mitre.org/detectionstrategies/DET0196#AN0566","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"network, socket, and http logs","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"macos-unifiedlog"},{"name":"macos:osquery","channel":"process_events","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-osquery"}],"mutable_elements":[{"field":"UnsignedBinary","description":"Helps tune detection when unsigned apps initiate fronted sessions."},{"field":"HostHeaderMatch","description":"Threshold to flag inconsistent domain targeting in encrypted sessions."},{"field":"SOCKSPortAnomaly","description":"Alert on unusual ports used in HTTPS+SOCKS activity patterns."}],"live":true,"detection_strategies":["DET0196"],"techniques":["T1090.004"]},{"id":"AN0567","stix_id":"x-mitre-analytic--4192b311-da7a-4ef1-b09a-a03a8c2a1670","name":"Analytic 0567","description":"Traffic originating from ESXi hosts or management interfaces displays SNI-to-Host mismatch behavior, particularly anomalous given typical infrastructure communication patterns.","url":"https://attack.mitre.org/detectionstrategies/DET0196#AN0567","platforms":["ESXi"],"log_source_references":[{"name":"NSM:Firewall","channel":"TLS/HTTP inspection","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"nsm-firewall"},{"name":"esxi:shell","channel":"/var/log/vmkernel.log, /var/log/vmkwarning.log","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"esxi-shell"}],"mutable_elements":[{"field":"AdminPortAccess","description":"ESXi hosts should rarely initiate external HTTPS—threshold to alert."},{"field":"TLSHandshakeOutliers","description":"Define entropy or timing anomalies for TLS handshake."},{"field":"DomainMismatchThreshold","description":"SNI/Host mismatch occurrence tolerance."}],"live":true,"detection_strategies":["DET0196"],"techniques":["T1090.004"]}],"live":true,"version":"1.0","techniques":["T1090.004"]}],"sigma_rules":[{"id":"8cb4d14e-776e-43c2-8fb9-91e7fcea32b4","title":"Potentially Suspicious Azure Front Door Connection","author":"Isaac Dunham","status":"test","level":"medium","date":"2024-11-07","modified":null,"description":"Detects connections with Azure Front Door (known legitimate service that can be leveraged for C2)\nthat fall outside of known benign behavioral baseline (not using common apps or common azurefd.net endpoints)\n","references":["https://lots-project.com/site/2a2e617a75726566642e6e6574","https://medium.com/r3d-buck3t/red-teaming-in-cloud-leverage-azure-frontdoor-cdn-for-c2-redirectors-79dd9ca98178","https://www.fortalicesolutions.com/posts/hiding-behind-the-front-door-with-azure-domain-fronting"],"logsource":{"product":"windows","category":"network_connection"},"tags":["attack.command-and-control","attack.t1102.002","attack.t1090.004","detection.threat-hunting"],"path":"rules-threat-hunting/windows/network_connection/net_connection_win_susp_azurefd_connection.yml","techniques":["T1102.002","T1090.004"],"cves":[]}],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}