Skip to content

MITRE ATT&CK

25 rules detecting network flows that match MITRE ATT&CK v18.1 techniques across 5 tactics: Initial Access, Command and Control, Lateral Movement, Exfiltration, and Discovery.

Initial Access

Rule IDSeverityTechniqueCategorySummary
ATK-T1133-01CRITICALT1133External Remote ServicesRDP exposed to external/any source
ATK-T1133-02HIGHT1133External Remote ServicesSSH exposed to external/any source
ATK-T1133-03HIGHT1133External Remote ServicesVNC exposed to external/any source
ATK-T1133-04HIGHT1133External Remote ServicesWinRM exposed to external/any source
ATK-T1133-05HIGHT1133External Remote ServicesCitrix ICA/HDX exposed to external/any source

Command and Control

Rule IDSeverityTechniqueCategorySummary
ATK-T1071-01MEDIUMT1071.001Application Layer ProtocolUnrestricted outbound HTTP/HTTPS to external
ATK-T1071-02HIGHT1071.004Application Layer ProtocolDirect external DNS (UDP) bypassing internal resolvers
ATK-T1071-03HIGHT1071.004Application Layer ProtocolDirect external DNS (TCP) bypassing internal resolvers

Lateral Movement

Rule IDSeverityTechniqueCategorySummary
ATK-T1021-01HIGHT1021.001Remote ServicesRDP from broad internal source
ATK-T1021-02CRITICALT1021.002Remote ServicesSMB from external/any source
ATK-T1021-03HIGHT1021.002Remote ServicesSMB from broad internal source
ATK-T1021-04HIGHT1021.002Remote ServicesNetBIOS from external/any source
ATK-T1021-05CRITICALT1021.006Remote ServicesWinRM HTTP from external/any source
ATK-T1021-06HIGHT1021.006Remote ServicesWinRM HTTPS from external/any source
ATK-T1021-07HIGHT1021.006Remote ServicesWinRM from broad internal source
ATK-T1021-08HIGHT1021.003Remote ServicesDCOM/RPC from broad internal source
ATK-T1021-09MEDIUMT1021.004Remote ServicesSSH from broad internal source
ATK-T1021-10HIGHT1021.005Remote ServicesVNC from broad internal source

Exfiltration

Rule IDSeverityTechniqueCategorySummary
ATK-T1048-01HIGHT1048Exfiltration Over Alternative ProtocolOutbound FTP to external
ATK-T1048-02HIGHT1048Exfiltration Over Alternative ProtocolOutbound SMTP to external
ATK-T1048-03CRITICALT1048Exfiltration Over Alternative ProtocolOutbound SMB to external
ATK-T1048-04HIGHT1048Exfiltration Over Alternative ProtocolOutbound DNS to external

Discovery

Rule IDSeverityTechniqueCategorySummary
ATK-T1018-01MEDIUMT1018Remote System DiscoveryICMP from broad source to broad/any destination
ATK-T1046-01HIGHT1046Network Service DiscoveryWide TCP port range between internal hosts
ATK-T1046-02MEDIUMT1046Network Service DiscoveryWide UDP port range between internal hosts