Detecttechnique
D3-PHDURAPer Host Download-Upload Ratio Analysis
Per Host Download-Upload Ratio Analysis
Definition
Detecting anomalies that indicate malicious activity by comparing the amount of data downloaded versus data uploaded by a host.
Defends against72
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Technique | Browser Session Hijackingt1185 | 100% | live |
| SubTechnique | Domain Frontingt1090.004 | 100% | live |
| Technique | Exfiltration Over C2 Channelt1041 | 100% | live |
| SubTechnique | Symmetric Cryptographyt1573.001 | 100% | live |
| Technique | Automated Exfiltrationt1020 | 100% | live |
| Technique | Lateral Tool Transfert1570 | 100% | live |
| SubTechnique | Application Access Tokent1550.001 | 100% | live |
| Technique | BITS Jobst1197 | 100% | live |
| Technique | Data Encodingt1132 | 100% | live |
| Technique | Web Servicet1102 | 100% | live |
| SubTechnique | Windows Management Instrumentation Event Subscriptiont1546.003 | 100% | live |
| Technique | Exfiltration Over Web Servicet1567 | 100% | live |
| SubTechnique | Remote Desktop Protocolt1021.001 | 100% | live |
| SubTechnique | Spearphishing Linkt1566.002 | 100% | live |
| Technique | Remote Servicest1021 | 100% | live |
| Technique | Application Layer Protocolt1071 | 100% | live |
| SubTechnique | CMSTPt1218.003 | 100% | live |
| SubTechnique | Transmitted Data Manipulationt1565.002 | 100% | live |
| SubTechnique | File Transfer Protocolst1071.002 | 100% | live |
| SubTechnique | Web Protocolst1071.001 | 100% | live |
| SubTechnique | DCSynct1003.006 | 100% | live |
| Technique | Exploitation of Remote Servicest1210 | 100% | live |
| Technique | Protocol Tunnelingt1572 | 100% | live |
| Technique | Ingress Tool Transfert1105 | 100% | live |
| Technique | Remote System Discoveryt1018 | 100% | live |
| Technique | Data Obfuscationt1001 | 100% | live |
| SubTechnique | Malicious Linkt1204.001 | 100% | live |
| SubTechnique | Spearphishing Attachmentt1566.001 | 100% | live |
| SubTechnique | Credential Stuffingt1110.004 | 100% | live |
| Technique | Multi-Stage Channelst1104 | 100% | live |
Showing top 30 of 72 by confidence. Click any target to see the full neighbourhood.
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.