Detect Obfuscated C2 via Network Traffic Analysis

Technique Detected:  Data Obfuscation | T1001

ID: DET0053
Domains: Enterprise
Analytics: AN0144, AN0145, AN0146
Version: 1.0
Created: 21 October 2025
Last Modified: 21 October 2025

Analytics

AN0144

Detects excessive outbound traffic to remote host over HTTP(S) from uncommon or previously unseen processes.

Log Sources
Data Component Name Channel
Network Traffic Content (DC0085) NSM:Flow HTTP
Mutable Elements
Field Description
OutboundByteThreshold Defines threshold ratio of outbound to inbound bytes that signals possible obfuscation
ProcessAllowlist List of known legitimate network clients to exclude from anomaly checks

AN0145

Identifies custom or previously unseen userland processes initiating high-volume HTTP connections with low response volume.

Log Sources
Data Component Name Channel
Network Connection Creation (DC0082) auditd:SYSCALL connect
Mutable Elements
Field Description
UserProcessBaseline Defines what is considered abnormal for a user-initiated process context

AN0146

Flags unexpected user applications initiating long-lived HTTP(S) sessions with irregular traffic patterns.

Log Sources
Data Component Name Channel
Network Traffic Content (DC0085) macos:unifiedlog network flow
Process Creation (DC0032) macos:unifiedlog process
Mutable Elements
Field Description
SessionDuration Session length that exceeds average per-user expectations