{"id":"T1205","name":"Traffic Signaling","url":"https://attack.mitre.org/techniques/T1205","tactics":["stealth","persistence","command-and-control"],"platforms":["Linux","macOS","Network Devices","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0524","stix_id":"x-mitre-detection-strategy--1e601759-c5d1-45cc-97a1-972967426794","name":"Traffic Signaling (Port-knock / magic-packet → firewall or service activation) – T1205","url":"https://attack.mitre.org/detectionstrategies/DET0524","analytics":[{"id":"AN1448","stix_id":"x-mitre-analytic--0848a778-7bcf-48d9-a14a-d29d1e71e656","name":"Analytic 1448","description":"A remote host sends a short sequence of failed connection attempts (RST/ICMP unreachable) to a set of closed ports. Within a brief window the endpoint (a) adds/enables a firewall rule or (b) a sniffer-backed process begins listening or opens a new socket, after which a successful connection occurs. Also detects Wake-on-LAN magic packets seen on local segment.","url":"https://attack.mitre.org/detectionstrategies/DET0524#AN1448","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=3, 22","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Microsoft-Windows-Windows Firewall With Advanced Security/Firewall","channel":"EventCode=2004, 2005, 2006","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"wineventlog-microsoft-windows-windows-firewall-with-advanced-security-firewall"},{"name":"WinEventLog:PowerShell","channel":"EventCode=4103, 4104, 4105, 4106","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"wineventlog-powershell"}],"mutable_elements":[{"field":"TimeWindowKnock","description":"Window to correlate knock sequence → rule change → successful connect (e.g., 120s)."},{"field":"PortSequenceMinLen","description":"Minimum number of distinct closed ports hit before success (e.g., 3)."},{"field":"SuspiciousProcesses","description":"List of binaries that commonly toggle firewall/sniff (netsh.exe, powershell.exe, npcapservice.exe, windivert, rawsock tools)."},{"field":"AllowedFirewallChangers","description":"Service accounts or software update agents allowed to change firewall."},{"field":"WoLAllowedWindows","description":"Maintenance windows when magic packets are expected."}],"live":true,"detection_strategies":["DET0524"],"techniques":["T1205"]},{"id":"AN1449","stix_id":"x-mitre-analytic--2e7a9609-3e4b-477b-828f-f486561d7fa7","name":"Analytic 1449","description":"Closed-port knock sequence from a remote IP followed by on-host firewall change (iptables/nftables) or daemon starts listening (socket open) and a successful TCP/UDP connect. Optional detection of libpcap/raw-socket sniffers spawning to watch for secret values.","url":"https://attack.mitre.org/detectionstrategies/DET0524#AN1449","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve: Commands altering firewall or enabling listeners (iptables, nft, ufw, firewall-cmd, systemctl start *ssh*/*telnet*, ip route add, tcpdump, tshark)","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"},{"name":"auditd:SYSCALL","channel":"socket/bind: Process binds to a new local port shortly after knock","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"auditd-syscall"},{"name":"NSM:Flow","channel":"Knock pattern: multiple REJ/S0 to distinct closed ports then successful connection to service_port","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"nsm-flow"},{"name":"NSM:Flow","channel":"Packets with unusual flags or payloads outside established flows (e.g., WoL magic FF×6 + 16×MAC)","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"ServicePort","description":"Port that becomes available post-knock (e.g., 22/8022/2323)."},{"field":"KnockResetRatio","description":"Percentage of failed attempts with RST/ICMP vs SYN/SYN-ACK to qualify as closed-port probing."},{"field":"ProcessAllowList","description":"Automation expected to touch firewall/daemon configs (config-mgmt agents)."}],"live":true,"detection_strategies":["DET0524"],"techniques":["T1205"]},{"id":"AN1450","stix_id":"x-mitre-analytic--48d2effa-7fc0-4790-9cc9-bbe573c29301","name":"Analytic 1450","description":"Remote knock sequence followed by PF/socketfilterfw rule update or a background process listening on a new port; then a successful TCP session. Also flags WoL magic packets on local segment.","url":"https://attack.mitre.org/detectionstrategies/DET0524#AN1450","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"exec: Execution of /sbin/pfctl, /usr/libexec/ApplicationFirewall/socketfilterfw, ifconfig, tcpdump, npcap/libpcap consumers","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"Firewall rule enable/disable or listen socket changes","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"macos-unifiedlog"},{"name":"NSM:Flow","channel":"Closed-port hits followed by success from same src_ip","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"PFAnchorPaths","description":"Anchors or conf files monitored for change (/etc/pf.conf, /etc/pf.anchors/*)."},{"field":"DeveloperMode","description":"Reduce noise on dev endpoints compiling or testing PF rules."}],"live":true,"detection_strategies":["DET0524"],"techniques":["T1205"]},{"id":"AN1451","stix_id":"x-mitre-analytic--ac933d77-bdb6-45ed-8fb5-87bae6f225cb","name":"Analytic 1451","description":"Crafted ‘synful knock’ patterns toward routers/switches (same src hits interface/broadcast/network address on same port in short order) followed by ACL/telnet/SSH enablement or module change. Detect device image/ACL updates then a new mgmt session.","url":"https://attack.mitre.org/detectionstrategies/DET0524#AN1451","platforms":["Network Devices"],"log_source_references":[{"name":"networkdevice:syslog","channel":"Config/ACL/line vty changes, service enable (telnet/ssh/http(s)), module reloads","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"networkdevice-syslog"},{"name":"NSM:Flow","channel":"Port-knock pattern from one src to device unicast,broadcast,network addresses on same port within TimeWindowKnock","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"MgmtPortSet","description":"Ports whose sudden enablement should alert (23, 22, 2323, 80/443, 4786)."},{"field":"DeviceRole","description":"Applies different thresholds to core/edge/branch devices."}],"live":true,"detection_strategies":["DET0524"],"techniques":["T1205"]}],"live":true,"version":"1.0","techniques":["T1205"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}