-
Notifications
You must be signed in to change notification settings - Fork 167
/
Copy pathsend-data.yml
33 lines (33 loc) · 938 Bytes
/
send-data.yml
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
rule:
meta:
name: send data
namespace: communication
authors:
description: all known techniques for sending data to a potential C2 server
scopes:
static: function
dynamic: span of calls
mbc:
- Command and Control::C2 Communication::Send Data [B0030.001]
examples:
- BFB9B5391A13D0AFD787E87AB90F14F5:0x13145D60
features:
- or:
- and:
- os: windows
- or:
- match: send HTTP request
- match: send data on socket
- match: send file via HTTP
- match: send data to Internet
- and:
- os: linux
- or: # Require network bound socket.
- match: create TCP socket
- match: create UDP socket
- or:
- match: send HTTP request
- match: send data on socket
- match: send file via HTTP