T1071

Application Layer Protocol

Adversaries may communicate using application layer protocols to avoid detection by blending in with existing traffic.

ATT&CK / Command and Control

APT groups commonly use HTTPS for C2 communications, making traffic analysis difficult as it blends with legitimate web traffic.

Defense strategies

  • SSL/TLS inspection
  • DNS monitoring
  • Network segmentation
  • Proxy authentication

Detection methods

  • Analyze traffic patterns
  • Monitor for beaconing behavior
  • Track unusual protocol usage
  • Detect domain fronting

T1071 on MITRE ATT&CK ↗