kevmap

TechniquesT1071.001 › AN0076

AN0076 Analytic 0076

Linux · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Detects curl, wget, Python requests, or custom HTTP clients communicating over non-standard ports, with repetitive or beacon-like patterns or POST-heavy behavior to rare domains.</p>
Detects
T1071.001 Web Protocols
Part of
DET0027 Detection of Web Protocol-Based C2 Over HTTP, HTTPS, or WebSockets

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
NSM:Flowhttp.log, conn.logDC0085 Network Traffic Content
auditd:SYSCALLexecveDC0032 Process Creation

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
CommandLinePatternMatchcurl or wget in scripts with suspicious domains or silent flags
BeaconIntervalWindowFixed-timed HTTP callbacks with 60±5s jitter

KEV CVEs whose mapped technique this analytic detects

CVEVendor / productState
CVE-2009-4324Adobe Acrobat and ReaderMapped
CVE-2015-3113Adobe Flash PlayerMapped
CVE-2015-5119Adobe Flash PlayerMapped
CVE-2021-35394Realtek Jungle Software Development Kit (SDK)Mapped
CVE-2021-40449Microsoft WindowsMapped
CVE-2022-42475Fortinet FortiOSMapped
CVE-2023-26360Adobe ColdFusionMapped
CVE-2023-38035Ivanti SentryMapped
CVE-2024-4577PHP Group PHPMapped
CVE-2024-4978Justice AV Solutions Viewer Mapped