{"id":"T1104","name":"Multi-Stage Channels","url":"https://attack.mitre.org/techniques/T1104","tactics":["command-and-control"],"platforms":["Linux","macOS","Windows","ESXi"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0228","stix_id":"x-mitre-detection-strategy--6368178a-04c5-490b-96d5-f12dcccd0497","name":"Detect Multi-Stage Command and Control Channels","url":"https://attack.mitre.org/detectionstrategies/DET0228","analytics":[{"id":"AN0637","stix_id":"x-mitre-analytic--f13ff1ad-5c7b-4136-b5cb-7a5663c3c54f","name":"Analytic 0637","description":"Initial process initiates outbound connection to first-stage C2, receives payloads or commands, then spawns or injects into a second process that establishes a new outbound connection to an unrelated destination (second-stage C2).","url":"https://attack.mitre.org/detectionstrategies/DET0228#AN0637","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=3, 22","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"TimeWindow","description":"Correlate two-stage behavior occurring within a short window (e.g., 1-5 minutes)"},{"field":"ParentProcess","description":"Tune to exclude known legitimate updaters and management agents"},{"field":"DestinationHostname","description":"May be customized to exclude known corporate domains and CDNs"}],"live":true,"detection_strategies":["DET0228"],"techniques":["T1104"]},{"id":"AN0638","stix_id":"x-mitre-analytic--e5fcc815-0ab4-4da9-aade-659b87d079da","name":"Analytic 0638","description":"Shell script or binary initiates curl/wget request to staging domain, writes output to disk or memory, and shortly afterward launches another process that establishes new outbound connection to a different IP or hostname.","url":"https://attack.mitre.org/detectionstrategies/DET0228#AN0638","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve, connect","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"},{"name":"iptables:LOG","channel":"OUTBOUND","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"iptables-log"}],"mutable_elements":[{"field":"BinaryPath","description":"Tune for suspicious binaries like curl, wget, python, netcat"},{"field":"IPDistance","description":"Detect multiple different external IPs contacted within short timeframe"}],"live":true,"detection_strategies":["DET0228"],"techniques":["T1104"]},{"id":"AN0639","stix_id":"x-mitre-analytic--53ba6028-13cd-449e-aab4-d2f9fea458a4","name":"Analytic 0639","description":"Initial process using NSURLSession or similar APIs reaches out to known staging domains, followed by creation of a reverse shell or RAT connecting to a second unrelated server.","url":"https://attack.mitre.org/detectionstrategies/DET0228#AN0639","platforms":["macOS"],"log_source_references":[{"name":"macos:endpointsecurity","channel":"ES_EVENT_TYPE_NOTIFY_EXEC","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-endpointsecurity"},{"name":"macos:unifiedlog","channel":"tcp/udp","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"UserContext","description":"Detect activity outside normal user behavior (e.g., automation or daemon context)"},{"field":"EntropyScore","description":"Optional for detecting encoded payloads delivered via stage 1"}],"live":true,"detection_strategies":["DET0228"],"techniques":["T1104"]},{"id":"AN0640","stix_id":"x-mitre-analytic--e8c91885-736e-4348-ba09-2acfbdd8b176","name":"Analytic 0640","description":"CLI-based or API-based network call from the hypervisor to external staging host, shortly followed by a connection to a second external IP by a spawned process or scheduled task.","url":"https://attack.mitre.org/detectionstrategies/DET0228#AN0640","platforms":["ESXi"],"log_source_references":[{"name":"esxi:hostd","channel":"CLI network calls","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"esxi-hostd"},{"name":"esxi:cron","channel":"process or cron activity","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"esxi-cron"}],"mutable_elements":[{"field":"ScheduledTaskName","description":"Detect unknown or obfuscated task names launching follow-up stages"},{"field":"DestinationIP","description":"Scope multiple IP destinations outside corporate ranges in short sequence"}],"live":true,"detection_strategies":["DET0228"],"techniques":["T1104"]}],"live":true,"version":"1.0","techniques":["T1104"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}