Detecttechnique
D3-APCAApplication Protocol Command Analysis
Application Protocol Command Analysis
Definition
Analyzing application protocol level remote commands to detect unauthorized activity.
Defends against72
| Type | Target | Confidence | Tier |
|---|---|---|---|
| SubTechnique | Internal Proxyt1090.001 | 100% | live |
| Technique | Remote Access Softwaret1219 | 100% | live |
| Technique | Browser Session Hijackingt1185 | 100% | live |
| Technique | Application Layer Protocolt1071 | 100% | live |
| Technique | Remote Service Session Hijackingt1563 | 100% | live |
| SubTechnique | Exfiltration Over Asymmetric Encrypted Non-C2 Protocolt1048.002 | 100% | live |
| SubTechnique | Domain Frontingt1090.004 | 100% | live |
| Technique | Exfiltration Over Other Network Mediumt1011 | 100% | live |
| SubTechnique | Symmetric Cryptographyt1573.001 | 100% | live |
| SubTechnique | CMSTPt1218.003 | 100% | live |
| Technique | Exfiltration Over Alternative Protocolt1048 | 100% | live |
| SubTechnique | Web Protocolst1071.001 | 100% | live |
| SubTechnique | Direct Network Floodt1498.001 | 100% | live |
| SubTechnique | Credential Stuffingt1110.004 | 100% | live |
| Technique | Adversary-in-the-Middlet1557 | 100% | live |
| Technique | Traffic Signalingt1205 | 100% | live |
| Technique | Dynamic Resolutiont1568 | 100% | live |
| Technique | Data Encodingt1132 | 100% | live |
| SubTechnique | Service Exhaustion Floodt1499.002 | 100% | live |
| SubTechnique | External Proxyt1090.002 | 100% | live |
| Technique | Drive-by Compromiset1189 | 100% | live |
| SubTechnique | Transmitted Data Manipulationt1565.002 | 100% | live |
| SubTechnique | Remote Desktop Protocolt1021.001 | 100% | live |
| SubTechnique | Additional Cloud Credentialst1098.001 | 100% | live |
| SubTechnique | Reflection Amplificationt1498.002 | 100% | live |
| SubTechnique | Mail Protocolst1071.003 | 100% | live |
| Technique | Data Transfer Size Limitst1030 | 100% | live |
| Technique | Scheduled Transfert1029 | 100% | live |
| Technique | Trusted Relationshipt1199 | 100% | live |
| Technique | Non-Application Layer Protocolt1095 | 100% | live |
Showing top 30 of 72 by confidence. Click any target to see the full neighbourhood.
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.