ATT&CKMatrixCommand and Control

Command and Control

TA0011

Tactic.View on attack.mitre.org

About this tactic

The adversary is trying to communicate with compromised systems to control them.

Command and Control consists of techniques that adversaries may use to communicate with systems under their control within a victim network. Adversaries commonly attempt to mimic normal, expected traffic to avoid detection. There are many ways an adversary can establish command and control with various levels of stealth depending on the victim’s network structure and defenses.

Techniques18

IDNameSub-techniquesExamples
T1001Data Obfuscation368
T1008Fallback Channels057
T1071Application Layer Protocol5547
T1090Proxy4182
T1092Communication Through Removable Media03
T1095Non-Application Layer Protocol0108
T1102Web Service3142
T1104Multi-Stage Channels015
T1105Ingress Tool Transfer0520
T1132Data Encoding2152
T1205Traffic Signaling233
T1219Remote Access Tools340
T1568Dynamic Resolution355
T1571Non-Standard Port066
T1572Protocol Tunneling042
T1573Encrypted Channel2299
T1659Content Injection02
T1665Hide Infrastructure08

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.