// MITRE ATT&CK
T1071 · Application Layer Protocol
Adversaries may communicate using OSI application layer protocols to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server. Adversari...
How to detect & mitigate it
Detecting Application Layer Protocol starts with your SIEM/EDR telemetry. Write a detection rule with the Sigma generator, analyze suspicious logs in the log analyzer, and place the technique on your coverage with the ATT&CK matrix.
Sub-techniques (5)
T1071.001
Web Protocols T1071.002
File Transfer Protocols T1071.003
Mail Protocols T1071.004
DNS T1071.005
Publish/Subscribe Protocols
Web Protocols T1071.002
File Transfer Protocols T1071.003
Mail Protocols T1071.004
DNS T1071.005
Publish/Subscribe Protocols
Related techniques
T1132.001
Standard Encoding T1568.002
Domain Generation Algorithms T1071.004
DNS T1071.005
Publish/Subscribe Protocols T1573.001
Symmetric Cryptography T1568.001
Fast Flux DNS T1219
Remote Access Tools T1572
Protocol Tunneling
Standard Encoding T1568.002
Domain Generation Algorithms T1071.004
DNS T1071.005
Publish/Subscribe Protocols T1573.001
Symmetric Cryptography T1568.001
Fast Flux DNS T1219
Remote Access Tools T1572
Protocol Tunneling
Source: MITRE ATT&CK®. ATT&CK is a registered trademark of The MITRE Corporation. Content for educational purposes.