Techniques › T1041
T1041 Exfiltration Over C2 Channel
exfiltration — ESXi, Linux, macOS, Windows · attack.mitre.org · JSON
1
MITRE detection strategy
4
analytics
5
Sigma rules tagged attack.t1041
12
KEV CVEs mapped here
<p>Adversaries may steal data by exfiltrating it over an existing command and control channel. Stolen data is encoded into the normal communications channel using the same protocol as command and control communications.</p>
KEV CVEs mapped to this technique · CTID Mappings Explorer
| CVE | Vendor / product | Mapping type | State | Added |
|---|---|---|---|---|
| CVE-2025-33053 | Microsoft Windows | secondary impact | Mapped | 2025-06-10 |
| CVE-2024-27443 | Synacor Zimbra Collaboration Suite (ZCS) | secondary impact | Mapped | 2025-05-19 |
| CVE-2025-32756 | Fortinet Multiple Products | secondary impact | Mapped | 2025-05-14 |
| CVE-2024-55550 | Mitel MiCollab | secondary impact | Mapped | 2025-01-07 |
| CVE-2024-4577 | PHP Group PHP | secondary impact | Mapped | 2024-06-12 |
| CVE-2023-5631 | Roundcube Webmail | secondary impact | Mapped | 2023-10-26 |
| CVE-2023-38831 | RARLAB WinRAR | secondary impact | Mapped | 2023-08-24 |
| CVE-2023-2868 | Barracuda Networks Email Security Gateway (ESG) Appliance | secondary impact | Mapped | 2023-05-26 |
| CVE-2023-1389 | TP-Link Archer AX21 | secondary impact | Mapped | 2023-05-01 |
| CVE-2018-4878 | Adobe Flash Player | secondary impact | Mapped | 2021-11-03 |
| CVE-2019-0604 | Microsoft SharePoint | primary impact | Mapped | 2021-11-03 |
| CVE-2019-18935 | Progress Telerik UI for ASP.NET AJAX | primary impact | Mapped | 2021-11-03 |
Detection strategy · ATT&CK Enterprise v19.2
- DET0348 Detection Strategy for Exfiltration Over C2 Channel v1.0
AN0988 WindowsIdentifies suspicious outbound traffic volume mismatches from processes that typically do not generate network activity, particularly over C2 protocols like HTTPS, DNS, or custom TCP/UDP ports, following file or data access.Tunable:
DataVolumeThresholdKnownBenignProcessesAN0989 LinuxMonitors for processes reading sensitive files then immediately initiating unusual outbound connections or bulk transfer sessions over persistent sockets, particularly with encrypted or binary payloads.Tunable:OutboundEntropyScoreConnectionDurationAN0990 macOSDetects unauthorized applications or scripts accessing sensitive data followed by establishing encrypted outbound communication to rare external destinations or with abnormal byte ratios.Tunable:ParentProcessAncestryProtocolListAN0991 ESXiDetects VMs sending outbound traffic through non-standard services or to unknown destinations. Exfiltration over reverse shells tunneled via VMkernel or custom payloads routed via hostd/vpxa.Tunable:GuestOSAllowListTransferSizeThresholdMBProtocolAllowList
Sigma rules · SigmaHQ da9bb07d64, tag attack.t1041
Author: Florian Roth (Nextron Systems)
· 2024-05-31 · logsource: product=windows category=network_connection · 07837ab9-60e1-481f-a74d-c31fb496a94c
Detects an executable accessing the portmap.io domain, which could be a sign of forbidden C2 traffic or data exfiltration by malicious actors
Author: Florian Roth (Nextron Systems)
· 2017-04-15 (modified 2021-11-27) · logsource: category=firewall · 881834a4-6659-4773-821e-1c151789d873
Detects communication to C2 servers mentioned in the operational notes of the ShadowBroker leak of EquationGroup C2 tools
Author: Security Onion Solutions
· 2024-03-08 · logsource: product=opencanary category=application · b4e6b016-a2ac-4759-ad85-8000b300d61e
Detects instances where a TFTP service on an OpenCanary node has had a request.
Author: Daniil Yugoslavskiy, oscd.community
· 2019-10-24 (modified 2024-01-18) · logsource: product=windows category=process_creation · c75309a3-59f8-4a8d-9c2c-4c927ad50555
Detects the execution of well known tools that can be abused for data exfiltration and tunneling.
Author: Swachchhanda Shrawan Poudel (Nextron Systems)
· 2025-09-24 · logsource: product=linux category=process_creation · efd2eb09-b72e-4a61-8dc7-b1382a1e8983
Detects potential Shai Hulud NPM package attack attempting to exfiltrate data via curl to external webhook sites.