Detecttechnique
D3-NTSANetwork Traffic Signature Analysis
Network Traffic Signature Analysis
Definition
Analyzing network traffic and compares it to known signatures
Defends against72
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Technique | Non-Standard Portt1571 | 100% | live |
| Technique | Drive-by Compromiset1189 | 100% | live |
| SubTechnique | Web Protocolst1071.001 | 100% | live |
| Technique | Fallback Channelst1008 | 100% | live |
| Technique | Dynamic Resolutiont1568 | 100% | live |
| Technique | Trusted Relationshipt1199 | 100% | live |
| SubTechnique | Service Exhaustion Floodt1499.002 | 100% | live |
| SubTechnique | CMSTPt1218.003 | 100% | live |
| SubTechnique | Credential Stuffingt1110.004 | 100% | live |
| Technique | BITS Jobst1197 | 100% | live |
| Technique | Remote Servicest1021 | 100% | live |
| SubTechnique | Internal Proxyt1090.001 | 100% | live |
| Technique | Exfiltration Over C2 Channelt1041 | 100% | live |
| SubTechnique | Multi-hop Proxyt1090.003 | 100% | live |
| SubTechnique | Application Access Tokent1550.001 | 100% | live |
| Technique | Adversary-in-the-Middlet1557 | 100% | live |
| SubTechnique | Domain Frontingt1090.004 | 100% | live |
| SubTechnique | External Proxyt1090.002 | 100% | live |
| SubTechnique | DNSt1071.004 | 100% | live |
| Technique | Encrypted Channelt1573 | 100% | live |
| Technique | Remote Service Session Hijackingt1563 | 100% | live |
| Technique | Exfiltration Over Web Servicet1567 | 100% | live |
| Technique | Data Encodingt1132 | 100% | live |
| SubTechnique | Exfiltration to Cloud Storaget1567.002 | 100% | live |
| Technique | Exploit Public-Facing Applicationt1190 | 100% | live |
| SubTechnique | Spearphishing Linkt1566.002 | 100% | live |
| SubTechnique | Port Knockingt1205.001 | 100% | live |
| SubTechnique | Kerberoastingt1558.003 | 100% | live |
| SubTechnique | DHCP Spoofingt1557.003 | 100% | live |
| Technique | Exfiltration Over Alternative Protocolt1048 | 100% | live |
Showing top 30 of 72 by confidence. Click any target to see the full neighbourhood.
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.