Command & Control
Channel design and the traffic it produces. Every page pairs the implant side with the network artifact a defender is left holding.
9 techniques
T1021.002Windows09-04T1071.001Windows, Linux, macOS08-04T1071.001Windows, Linux, macOS08-04T1071.002Windows08-04T1071.004Windows, Linux, macOS08-04T1071.004Windows, Linux, macOS08-04T1071.004Windows, Linux, macOS09-04T1090.004Windows, Linux, macOS08-04T1095Windows, Linux08-04
SMB / Windows Admin Share C2
Use admin shares and SMB file operations as a low-bandwidth command and control channel inside a LAN.
HTTP/S Beaconing
Use malleable HTTP profiles to make beacon traffic look like legitimate browser requests.
WebSocket C2 Channel
Use persistent WebSocket connections over HTTPS to maintain a full-duplex C2 channel that blends with web application traffic.
SMB Named Pipe C2
Route implant traffic over SMB named pipes to blend with legitimate file-share traffic.
DNS Beaconing
Tunnel C2 traffic inside DNS queries so it blends with legitimate resolver noise.
DNS-over-HTTPS C2
Tunnel C2 traffic through DNS-over-HTTPS providers, encrypting DNS queries so network sensors cannot inspect subdomain labels.
LDAP C2
Steer an implant over LDAP, using the directory protocol's bind and search operations as the beacon.
HTTPS Domain Fronting
Route C2 traffic through a trusted CDN provider so network defenders see connections to a legitimate host while traffic reaches the attacker's server.
ICMP Tunneling
Smuggle C2 data inside ICMP Echo request and reply payloads to bypass application-layer filtering.
no techniques match those filters.