{"id":"T1001.001","name":"Junk Data","url":"https://attack.mitre.org/techniques/T1001/001","tactics":["command-and-control"],"platforms":["ESXi","Linux","macOS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0011","stix_id":"x-mitre-detection-strategy--bb40d0a9-b35b-4adc-8a69-a3002d53f5f7","name":"Detecting Junk Data in C2 Channels via Behavioral Analysis","url":"https://attack.mitre.org/detectionstrategies/DET0011","analytics":[{"id":"AN0030","stix_id":"x-mitre-analytic--3e852bb9-785d-4bc4-9f7e-b7e43a5d8bc8","name":"Analytic 0030","description":"Processes generating large outbound connections with disproportionate send/receive ratios, often to uncommon ports or hosts, potentially inserting meaningless data into protocol payloads.","url":"https://attack.mitre.org/detectionstrategies/DET0011#AN0030","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=3, 22","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=10","data_component":"DC0035","data_component_name":"Process Access","log_source_slug":"wineventlog-sysmon"},{"name":"NSM:Flow","channel":"TCP/UDP","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"PayloadEntropyThreshold","description":"Tunable threshold for Shannon entropy of network payloads."},{"field":"TimeWindow","description":"Duration of outbound data transfer to evaluate disproportionate upload size."},{"field":"UserContext","description":"Filter based on user accounts allowed to generate outbound traffic."}],"live":true,"detection_strategies":["DET0011"],"techniques":["T1001.001"]},{"id":"AN0031","stix_id":"x-mitre-analytic--4c7d92bb-4b46-44e4-b070-43c46d3193c4","name":"Analytic 0031","description":"Outbound traffic with anomalous payload sizes and patterns from non-networking processes, often observed via packet inspection or connection logs.","url":"https://attack.mitre.org/detectionstrategies/DET0011#AN0031","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve network tools","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"},{"name":"NSM:Flow","channel":"TCP session tracking","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"EntropyScore","description":"Adjust based on expected entropy of typical outbound data."},{"field":"ProcessWhitelist","description":"Exclude known good binaries that generate high network output."},{"field":"DataRatioThreshold","description":"Minimum ratio of bytes_sent to bytes_received."}],"live":true,"detection_strategies":["DET0011"],"techniques":["T1001.001"]},{"id":"AN0032","stix_id":"x-mitre-analytic--0519edaf-6485-40b2-8b91-13db29fb8cb8","name":"Analytic 0032","description":"Previously unseen applications generating outbound connections with atypical data flow characteristics, such as excessive data with no return response.","url":"https://attack.mitre.org/detectionstrategies/DET0011#AN0032","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"connection attempts","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"macos-unifiedlog"},{"name":"macos:osquery","channel":"process_events","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-osquery"},{"name":"NSM:Flow","channel":"session behavior","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"ParentProcessCheck","description":"Allow filtering based on parent-child relationship for benign services."},{"field":"HostWhitelist","description":"Known legitimate C2-like patterns (e.g., Apple telemetry)."}],"live":true,"detection_strategies":["DET0011"],"techniques":["T1001.001"]},{"id":"AN0033","stix_id":"x-mitre-analytic--d3bad85b-9e86-4de8-9e4a-1666133af782","name":"Analytic 0033","description":"Anomalous traffic from ESXi host management daemons (like hostd or vpxa) embedding non-standard payloads in management protocols (e.g., HTTPS) or beaconing behavior.","url":"https://attack.mitre.org/detectionstrategies/DET0011#AN0033","platforms":["ESXi"],"log_source_references":[{"name":"esxi:vmkernel","channel":"Network activity","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"esxi-vmkernel"},{"name":"esxi:hostd","channel":"System service interactions","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"esxi-hostd"}],"mutable_elements":[{"field":"TLSFingerprintMismatch","description":"Detects mismatched TLS client behavior vs expected for hostd/vpxa."},{"field":"UnusualDestinationPorts","description":"Highlight traffic from ESXi hosts to uncommon ports outside vCenter ranges."}],"live":true,"detection_strategies":["DET0011"],"techniques":["T1001.001"]}],"live":true,"version":"1.0","techniques":["T1001.001"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}