Techniques › T1001 › T1001.003
T1001.003 Protocol or Service Impersonation
command and control — ESXi, Linux, macOS, Windows · attack.mitre.org · JSON
1
MITRE detection strategy
4
analytics
2
Sigma rules tagged attack.t1001.003
0
KEV CVEs mapped here
<p>Adversaries may impersonate legitimate protocols or web service traffic to disguise command and control activity and thwart analysis efforts. By impersonating legitimate protocols or web services, adversaries can make their command and control traffic blend in with legitimate network traffic.</p><p>Adversaries may impersonate a fake SSL/TLS handshake to make it look like subsequent traffic is SSL/TLS encrypted, potentially interfering with some security tooling, or to make the traffic look like it is related with a trusted entity.</p><p>Adversaries may also leverage legitimate protocols to impersonate expected web traffic or trusted services. For example, adversaries may manipulate HTTP headers, URI endpoints, SSL certificates, and transmitted data to disguise C2 communications or mimic legitimate services such as Gmail, Google Drive, and Yahoo Messenger.</p>
KEV CVEs mapped to this technique · CTID Mappings Explorer
None. No KEV entry in the public mapping names this technique. Given that 74.7% of KEV has no mapping at all, this says more about the mapping than about the technique.
Detection strategy · ATT&CK Enterprise v19.2
- DET0470 Detecting Protocol or Service Impersonation via Anomalous TLS, HTTP Header, and Port Mismatch Correlation v1.0
AN1294 WindowsUntrusted processes creating outbound TLS/HTTPS connections with malformed certificates or header fields, often mismatched with target service behavior. Detects protocol impersonation attempts via traffic metadata analysis and host process lineage.Tunable:
IssuerOrgFilterUserContextHeaderSignatureMatchAN1295 LinuxDetection of binaries spawning encrypted sessions using OpenSSL or curl to external services with mismatched ports/protocols. Identifies behavior where internal services simulate trusted cloud service traffic patterns.Tunable:ProtocolMatchConfidenceTimeWindowAN1296 macOSUnsigned or suspicious applications initiating network traffic claiming to be browser, mail, or cloud clients. Detects impersonation via TLS fingerprint and User-Agent string deviation.Tunable:ParentProcessFilterHeaderAnomalyScoreAN1297 ESXiESXi hosts initiating connections from non-standard daemons mimicking HTTP/HTTPS or SNMP traffic, but with irregular payload formats or expired/unsigned TLS certificates.Tunable:TLSFingerprintMatchAllowedServicePorts
Sigma rules · SigmaHQ da9bb07d64, tag attack.t1001.003
Author: xknow @xknow_infosec, Tim Shelton
· 2019-03-24 (modified 2023-10-18) · logsource: product=windows category=file_event · 75bf09fa-1dd7-4d18-9af9-dd9e492562eb
Detects the creation of an "Active Directory Schema Cache File" (.sch) file by an uncommon tool.
Author: xknow @xknow_infosec
· 2019-03-24 (modified 2022-10-05) · logsource: product=windows service=security · d00a9a72-2c09-4459-ad03-5e0a23351e36
Detects the usage of particular AttributeLDAPDisplayNames, which are known for data exchange via LDAP by the tool LDAPFragger and are additionally not commonly used in companies.