Detecttechnique

D3-NTCDNetwork Traffic Community Deviation

Network Traffic Community Deviation

Definition

Establishing baseline communities of network hosts and identifying statistically divergent inter-community communication.

Defends against72

TypeTargetConfidenceTier
TechniqueIngress Tool Transfert1105100%live
TechniqueData Encodingt1132100%live
TechniqueDynamic Resolutiont1568100%live
SubTechniqueExfiltration to Cloud Storaget1567.002100%live
TechniqueData Transfer Size Limitst1030100%live
TechniqueAutomated Exfiltrationt1020100%live
TechniqueData Obfuscationt1001100%live
SubTechniqueCredential Stuffingt1110.004100%live
TechniqueDrive-by Compromiset1189100%live
TechniqueExfiltration Over Web Servicet1567100%live
SubTechniqueWeb Session Cookiet1550.004100%live
TechniqueFallback Channelst1008100%live
TechniqueBrowser Session Hijackingt1185100%live
TechniqueApplication Layer Protocolt1071100%live
TechniqueProtocol Tunnelingt1572100%live
SubTechniqueExfiltration to Code Repositoryt1567.001100%live
SubTechniqueWindows Management Instrumentation Event Subscriptiont1546.003100%live
SubTechniqueDNSt1071.004100%live
TechniqueAdversary-in-the-Middlet1557100%live
SubTechniqueInternal Proxyt1090.001100%live
SubTechniqueKerberoastingt1558.003100%live
TechniqueScheduled Transfert1029100%live
SubTechniqueAsymmetric Cryptographyt1573.002100%live
SubTechniqueSSHt1021.004100%live
TechniqueWeb Servicet1102100%live
SubTechniqueDirect Network Floodt1498.001100%live
TechniqueRemote Service Session Hijackingt1563100%live
SubTechniqueAdditional Cloud Credentialst1098.001100%live
SubTechniqueMail Protocolst1071.003100%live
TechniqueExfiltration Over C2 Channelt1041100%live

Showing top 30 of 72 by confidence. Click any target to see the full neighbourhood.

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Defence
Network Traffic Analysis
Defence
Network Traffic Filtering
Defence
IPC Traffic Analysis
Defence
Network Traffic Signature Analysis
Defence
Protocol Metadata Anomaly Detection
Defence
Network Traffic Policy Mapping
Sourced from MITRE D3FEND ontology. Curated by Adam Lundqvist, SQUR.