kevmap

Techniques › T1041

T1041 Exfiltration Over C2 Channel

exfiltration — ESXi, Linux, macOS, Windows · attack.mitre.org · JSON

1
MITRE detection strategy
4
analytics
5
Sigma rules tagged attack.t1041
12
KEV CVEs mapped here
<p>Adversaries may steal data by exfiltrating it over an existing command and control channel. Stolen data is encoded into the normal communications channel using the same protocol as command and control communications.</p>

KEV CVEs mapped to this technique · CTID Mappings Explorer

CVEVendor / productMapping typeStateAdded
CVE-2025-33053Microsoft Windows secondary impact Mapped2025-06-10
CVE-2024-27443Synacor Zimbra Collaboration Suite (ZCS) secondary impact Mapped2025-05-19
CVE-2025-32756Fortinet Multiple Products secondary impact Mapped2025-05-14
CVE-2024-55550Mitel MiCollab secondary impact Mapped2025-01-07
CVE-2024-4577PHP Group PHP secondary impact Mapped2024-06-12
CVE-2023-5631Roundcube Webmail secondary impact Mapped2023-10-26
CVE-2023-38831RARLAB WinRAR secondary impact Mapped2023-08-24
CVE-2023-2868Barracuda Networks Email Security Gateway (ESG) Appliance secondary impact Mapped2023-05-26
CVE-2023-1389TP-Link Archer AX21 secondary impact Mapped2023-05-01
CVE-2018-4878Adobe Flash Player secondary impact Mapped2021-11-03
CVE-2019-0604Microsoft SharePoint primary impact Mapped2021-11-03
CVE-2019-18935Progress Telerik UI for ASP.NET AJAX primary impact Mapped2021-11-03

Detection strategy · ATT&CK Enterprise v19.2

Sigma rules · SigmaHQ da9bb07d64, tag attack.t1041

Author: Florian Roth (Nextron Systems) · 2024-05-31 · logsource: product=windows category=network_connection · 07837ab9-60e1-481f-a74d-c31fb496a94c
Detects an executable accessing the portmap.io domain, which could be a sign of forbidden C2 traffic or data exfiltration by malicious actors
Techniques: T1041T1090.002
Author: Florian Roth (Nextron Systems) · 2017-04-15 (modified 2021-11-27) · logsource: category=firewall · 881834a4-6659-4773-821e-1c151789d873
Detects communication to C2 servers mentioned in the operational notes of the ShadowBroker leak of EquationGroup C2 tools
Techniques: T1041
Author: Security Onion Solutions · 2024-03-08 · logsource: product=opencanary category=application · b4e6b016-a2ac-4759-ad85-8000b300d61e
Detects instances where a TFTP service on an OpenCanary node has had a request.
Techniques: T1041
Author: Daniil Yugoslavskiy, oscd.community · 2019-10-24 (modified 2024-01-18) · logsource: product=windows category=process_creation · c75309a3-59f8-4a8d-9c2c-4c927ad50555
Detects the execution of well known tools that can be abused for data exfiltration and tunneling.
Author: Swachchhanda Shrawan Poudel (Nextron Systems) · 2025-09-24 · logsource: product=linux category=process_creation · efd2eb09-b72e-4a61-8dc7-b1382a1e8983
Detects potential Shai Hulud NPM package attack attempting to exfiltrate data via curl to external webhook sites.
Techniques: T1041T1005