Detecttechnique
D3-CSPPClient-server Payload Profiling
Client-server Payload Profiling
Definition
Comparing client-server request and response payloads to a baseline profile to identify outliers.
Defends against72
| Type | Target | Confidence | Tier |
|---|---|---|---|
| SubTechnique | Direct Network Floodt1498.001 | 100% | live |
| SubTechnique | LLMNR/NBT-NS Poisoning and SMB Relayt1557.001 | 100% | live |
| SubTechnique | Exfiltration to Code Repositoryt1567.001 | 100% | live |
| Technique | Non-Standard Portt1571 | 100% | live |
| Technique | Dynamic Resolutiont1568 | 100% | live |
| Technique | Remote Access Softwaret1219 | 100% | live |
| SubTechnique | Exfiltration Over Unencrypted Non-C2 Protocolt1048.003 | 100% | live |
| SubTechnique | Spearphishing Linkt1566.002 | 100% | live |
| Technique | Non-Application Layer Protocolt1095 | 100% | live |
| SubTechnique | Exfiltration to Cloud Storaget1567.002 | 100% | live |
| Technique | Windows Management Instrumentationt1047 | 100% | live |
| SubTechnique | Application Access Tokent1550.001 | 100% | live |
| Technique | Lateral Tool Transfert1570 | 100% | live |
| SubTechnique | Web Protocolst1071.001 | 100% | live |
| Technique | Protocol Tunnelingt1572 | 100% | live |
| SubTechnique | Exfiltration Over Asymmetric Encrypted Non-C2 Protocolt1048.002 | 100% | live |
| SubTechnique | Additional Cloud Credentialst1098.001 | 100% | live |
| Technique | Exfiltration Over C2 Channelt1041 | 100% | live |
| SubTechnique | Reflection Amplificationt1498.002 | 100% | live |
| SubTechnique | Credential Stuffingt1110.004 | 100% | live |
| Technique | Remote Servicest1021 | 100% | live |
| SubTechnique | Accessibility Featurest1546.008 | 100% | live |
| SubTechnique | Domain Frontingt1090.004 | 100% | live |
| Technique | Data Encodingt1132 | 100% | live |
| SubTechnique | TFTP Boott1542.005 | 100% | live |
| SubTechnique | Windows Management Instrumentation Event Subscriptiont1546.003 | 100% | live |
| SubTechnique | External Proxyt1090.002 | 100% | live |
| Technique | Scheduled Transfert1029 | 100% | live |
| Technique | Ingress Tool Transfert1105 | 100% | live |
| Technique | Remote System Discoveryt1018 | 100% | live |
Showing top 30 of 72 by confidence. Click any target to see the full neighbourhood.
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.