kevmap

TechniquesT1027 › AN1067

AN1067 Analytic 1067

Network Devices · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Identifies transfer of base64, uuencoded, or high-entropy files over HTTP, FTP, or custom protocols in lateral movement or exfiltration streams.</p>
Detects
T1027 Obfuscated Files or Information
Part of
DET0378 Behavioral Detection of Obfuscated Files or Information

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
networkdevice:IDScontent inspection / PCAP / HTTP bodyDC0085 Network Traffic Content

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
EntropyThresholdAdjust threshold to reduce false positives in compressed but benign data
ProtocolScopeRefine by enabling inspection of specific exfil vectors (e.g., FTP, HTTP POST)

KEV CVEs whose mapped technique this analytic detects

CVEVendor / productState
CVE-2010-2883Adobe Acrobat and ReaderMapped
CVE-2021-40449Microsoft WindowsMapped
CVE-2021-40539Zoho ManageEngineMapped
CVE-2021-44077Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter PlusMapped
CVE-2022-24086Adobe Commerce and Magento Open SourceMapped