Tactic.View on attack.mitre.org
The adversary is trying to communicate with compromised systems to control them.
Command and Control consists of techniques that adversaries may use to communicate with systems under their control within a victim network. Adversaries commonly attempt to mimic normal, expected traffic to avoid detection. There are many ways an adversary can establish command and control with various levels of stealth depending on the victim’s network structure and defenses.
| ID | Name | Sub-techniques | Examples |
|---|---|---|---|
| T1001 | Data Obfuscation | 3 | 68 |
| T1008 | Fallback Channels | 0 | 57 |
| T1071 | Application Layer Protocol | 5 | 547 |
| T1090 | Proxy | 4 | 182 |
| T1092 | Communication Through Removable Media | 0 | 3 |
| T1095 | Non-Application Layer Protocol | 0 | 108 |
| T1102 | Web Service | 3 | 142 |
| T1104 | Multi-Stage Channels | 0 | 15 |
| T1105 | Ingress Tool Transfer | 0 | 520 |
| T1132 | Data Encoding | 2 | 152 |
| T1205 | Traffic Signaling | 2 | 33 |
| T1219 | Remote Access Tools | 3 | 40 |
| T1568 | Dynamic Resolution | 3 | 55 |
| T1571 | Non-Standard Port | 0 | 66 |
| T1572 | Protocol Tunneling | 0 | 42 |
| T1573 | Encrypted Channel | 2 | 299 |
| T1659 | Content Injection | 0 | 2 |
| T1665 | Hide Infrastructure | 0 | 8 |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.