Adversaries may establish command and control capabilities over commonly used application layer protocols such as HTTP(S), OPC, RDP, telnet, DNP3, and modbus. These protocols may be used to disguise adversary actions as benign network traffic. Standard protocols may be seen on their associated port or in some cases over a non-standard port. Adversaries may use these protocols to reach out of the network for command and control, or in some cases to other infected devices within the network.

Linked Issues

Issuelinks
Linktyp Issue
is related to Techniques
is related to Intelligent Electronic Device (IED)
is related to Programmable Logic Controller (PLC)
is related to Jump Host
is related to Control Server
is related to Data Gateway
is related to Application Server
is related to Workstation
is related to Programmable Automation Controller (PAC)
is related to Distributed Control System (DCS) Controller
is related to Switch
is related to Human-Machine Interface (HMI)
is related to Safety Controller
is related to Data Historian
is related to Firewall
is related to Remote Terminal Unit (RTU)
is related to Virtual Private Network (VPN) Server
is blocked by Network Segmentation
is blocked by Detection of Standard Application Layer Protocol
is blocked by Network Intrusion Prevention
is blocked by Network Allowlists
Impressum Deutsch Englisch