Detecttechnique
D3-PMADProtocol Metadata Anomaly Detection
Protocol Metadata Anomaly Detection
Definition
Collecting network communication protocol metadata and identifying statistical outliers.
Defends against72
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Technique | Windows Management Instrumentationt1047 | 100% | live |
| SubTechnique | Exfiltration Over Symmetric Encrypted Non-C2 Protocolt1048.001 | 100% | live |
| Technique | Exfiltration Over C2 Channelt1041 | 100% | live |
| SubTechnique | Application Access Tokent1550.001 | 100% | live |
| Technique | Trusted Relationshipt1199 | 100% | live |
| Technique | Automated Exfiltrationt1020 | 100% | live |
| SubTechnique | Spearphishing Linkt1566.002 | 100% | live |
| SubTechnique | Port Knockingt1205.001 | 100% | live |
| SubTechnique | Web Session Cookiet1550.004 | 100% | live |
| SubTechnique | Reflection Amplificationt1498.002 | 100% | live |
| SubTechnique | Service Exhaustion Floodt1499.002 | 100% | live |
| Technique | Data Obfuscationt1001 | 100% | live |
| SubTechnique | Direct Network Floodt1498.001 | 100% | live |
| SubTechnique | File Transfer Protocolst1071.002 | 100% | live |
| SubTechnique | Accessibility Featurest1546.008 | 100% | live |
| Technique | Data Transfer Size Limitst1030 | 100% | live |
| Technique | Non-Standard Portt1571 | 100% | live |
| SubTechnique | Kerberoastingt1558.003 | 100% | live |
| SubTechnique | Additional Cloud Credentialst1098.001 | 100% | live |
| Technique | Ingress Tool Transfert1105 | 100% | live |
| Technique | Dynamic Resolutiont1568 | 100% | live |
| SubTechnique | CMSTPt1218.003 | 100% | live |
| SubTechnique | Malicious Linkt1204.001 | 100% | live |
| Technique | Adversary-in-the-Middlet1557 | 100% | live |
| Technique | Exfiltration Over Other Network Mediumt1011 | 100% | live |
| Technique | Scheduled Transfert1029 | 100% | live |
| SubTechnique | Internal Proxyt1090.001 | 100% | live |
| Technique | Rogue Domain Controllert1207 | 100% | live |
| SubTechnique | Password Sprayingt1110.003 | 100% | live |
| Technique | Exploitation of Remote Servicest1210 | 100% | live |
Showing top 30 of 72 by confidence. Click any target to see the full neighbourhood.
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.