If you are not sure if the website you would like to visit is secure, you can verify it here. Enter the website address of the page and see parts of its content and the thumbnail images on this site. None (if any) dangerous scripts on the referenced page will be executed. Additionally, if the selected site contains subpages, you can verify it (review) in batches containing 5 pages.
favicon.ico: attack.mitre.org/techniques/T1071 - Application Layer Protocol, Te.

site address: attack.mitre.org/techniques/T1071 redirected to: attack.mitre.org/techniques/T1071

site title: Application Layer Protocol, Technique T1071 - Enterprise MITRE ATT&CK®

Our opinion (on Monday 24 August 2026 12:50:47 UTC):

GREEN status (no comments) - no comments
After content analysis of this website we propose the following hashtags:



Meta tags:

Headings (most frequently used words):

application, layer, protocol, procedure, examples, mitigations, detection, strategy, references, sub, techniques,

Text of the page (most frequently used words):
the (22), and (21), retrieved (19), for (14), protocols (13), 2024 (12), t1071 (12), traffic (11), att (10), all (10), network (10), may (9), layer (9), used (9), #protocol (9), application (8), use (7), enterprise (7), 2021 (7), malware (7), ics (6), detection (6), techniques (6), with (6), command (6), control (6), can (6), has (6), mobile (5), none (5), june (5), raspberry (5), robin (5), november (5), dns (5), over (5), irc (5), mitre (4), data (4), team (4), group (4), teamtnt (4), windows (4), 2020 (4), july (4), systems (4), detects (4), that (4), version (4), are (3), software (3), cti (3), mitigations (3), defenses (3), sub (3), threat (3), velvet (3), ant (3), march (3), 2025 (3), incident (3), sliver (3), siloscape (3), august (3), rocke (3), 2022 (3), 2023 (3), 2017 (3), february (3), magic (3), hound (3), lucifer (3), new (3), cryptojacking (3), high (3), devices (3), inc (3), ransom (3), hildegard (3), frostygoop (3), duqu (3), https (3), smb (3), description (3), name (3), filter (3), ssh (3), server (3), communication (3), adversaries (3), rdp (3), between (3), those (3), 2015 (2), 2026 (2), corporation (2), domains (2), resources (2), reference (2), campaigns (2), groups (2), components (2), analytics (2), strategies (2), assets (2), tactics (2), matrices (2), core (2), objects (2), cloud (2), september (2), response (2), many (2), targeting (2), april (2), files (2), december (2), targets (2), leverages (2), activity (2), like (2), embedded (2), http (2), using (2), abnormal (2), such (2), curl (2), suspicious (2), wget (2), custom (2), ports (2), analytic (2), intrusion (2), prevention (2), adversary (2), based (2), filtering (2), communicate (2), bot (2), communications (2), utilize (2), connection (2), quietexit (2), uses (2), tcp (2), nightdoor (2), neteagle (2), connections (2), commonly (2), clambling (2), october (2), 005 (2), 004 (2), 003 (2), 002 (2), 001 (2), web (2), mail (2), within (2), commands (2), ckcon (2), person (2), tickets (2), faq (2), registered, trademarks, cookie, preferences, website, changelog, privacy, policy, terms, contact, reset, filters, sygnia, china, nexus, abuses, load, balancers, persistence, fiser, oliveira, tracking, activities, closer, look, focused, malicious, actor, cybereason, global, soc, leveraged, actors, prizmant, first, known, containers, compromise, environments, liebenberg, 2018, champion, monero, miners, patrick, schläpfer, now, spreading, through, script, christopher, telecom, governments, lauren, podber, stef, rand, gets, worm, early, hunter, daggerfly, espionage, makes, major, update, toolset, ahn, facundo, muñoz, marc, etienne, léveillé, evasive, panda, monlam, festival, target, tibetans, dfir, report, exchange, exploit, leads, domain, wide, ransomware, january, lee, falcone, campaign, attacks, saudi, hsu, ddos, hybrid, exploiting, critical, vulnerabilities, infect, huntress, investigating, chen, kubernetes, mark, graham, carolyn, ahlers, kyle, meara, dragos, impact, connected, symantec, security, 2011, w32, precursor, next, stuxnet, lunghi, uncovering, drbcontrol, mandiant, unc3524, eye, spy, your, email, references, tunneling, unauthorized, app, tls, headers, misused, crossing, vlans, an1228, applications, volume, not, previously, associated, process, image, automator, applescript, invoking, python, sockets, an1227, socket, style, unbalanced, beacon, intervals, an1226, usage, common, processes, outbound, byte, counts, irregular, possibly, indicating, exfiltration, an1225, det0444, strategy, signatures, identify, specific, mitigate, level, m1031, appliances, ingress, egress, perform, configure, endpoints, m1037, mitigation, reverse, tunnels, victim, g1047, g0139, wireguard, vpn, s0633, connects, s0623, issued, requests, from, infected, g0106, capable, contacting, tor, delivering, second, stage, payloads, s1130, inverse, negotiated, part, its, s1084, udp, s1147, also, establish, controller, 7519, s0034, g0059, stratum, port, 10001, mining, s0532, valid, accounts, connect, targeted, g1032, channel, s0601, during, initiated, two, tunnelling, l2tp, moscow, addresses, c0041, communicates, frequently, encapsulated, s0038, ability, telnet, s0660, procedure, examples, live, permalink, last, modified, created, duane, michael, contributors, esxi, linux, macos, platforms, tactic, different, including, browsing, transferring, electronic, publishing, subscribing, occur, internally, enclave, proxy, pivot, node, other, nodes, osi, avoid, blending, existing, remote, system, often, results, will, client, publish, subscribe, file, transfer, home, open, join, mclean, hotel, location, details, found, register, here, search, blog, contribute, benefactors, legal, branding, updates, history, engage, tools, advisory, council, learn, more, about, get, started, detections, technique,


Text of the page (random words):
application layer protocol technique t1071 enterprise mitre att ck matrices enterprise mobile ics tactics enterprise mobile ics techniques enterprise mobile ics defenses mitigations enterprise mobile ics assets detections detection strategies analytics data components cti groups software campaigns resources get started learn more about att ck att ck advisory council att ckcon att ck data tools faq engage with att ck version history updates legal branding benefactors contribute blog search att ckcon 7 0 in person tickets are open join us october 27 28 2026 in mclean va register here for in person tickets hotel and location details can be found in the faq home techniques enterprise application layer protocol application layer protocol sub techniques 5 id name t1071 001 web protocols t1071 002 file transfer protocols t1071 003 mail protocols t1071 004 dns t1071 005 publish subscribe protocols adversaries may communicate using osi application layer protocols to avoid detection network filtering by blending in with existing traffic commands to the remote system and often the results of those commands will be embedded within the protocol traffic between the client and server adversaries may utilize many different protocols including those used for web browsing transferring files electronic mail dns or publishing subscribing for connections that occur internally within an enclave such as those between a proxy or pivot node and other nodes commonly used protocols are smb ssh or rdp 1 id t1071 sub techniques t1071 001 t1071 002 t1071 003 t1071 004 t1071 005 ⓘ tactic command and control ⓘ platforms esxi linux network devices windows macos contributors duane michael version 2 4 created 31 may 2017 last modified 24 october 2025 version permalink live version procedure examples id name description s0660 clambling clambling has the ability to use telnet for communication 2 s0038 duqu duqu uses a custom command and control protocol that communicates over commonly used ports and is frequently encapsulated by application layer protocols 3 c0041 frostygoop incident during frostygoop incident the adversary initiated layer two tunnelling protocol l2tp connections to moscow based ip addresses 4 s0601 hildegard hildegard has used an irc channel for c2 communications 5 g1032 inc ransom inc ransom has used valid accounts over rdp to connect to targeted systems 6 s0532 lucifer lucifer can use the stratum protocol on port 10001 for communication between the cryptojacking bot and the mining server 7 g0059 magic hound magic hound malware has used irc for c2 8 9 s0034 neteagle adversaries can also use neteagle to establish an rdp connection with a controller over tcp 7519 s1147 nightdoor nightdoor uses tcp and udp communication for command and control traffic 10 11 s1084 quietexit quietexit can use an inverse negotiated ssh connection as part of its c2 1 s1130 raspberry robin raspberry robin is capable of contacting the tor network for delivering second stage payloads 12 13 14 g0106 rocke rocke issued wget requests from infected systems to the c2 15 s0623 siloscape siloscape connects to an irc server for c2 16 s0633 sliver sliver can utilize the wireguard vpn protocol for command and control 17 g0139 teamtnt teamtnt has used an irc bot for c2 communications 18 g1047 velvet ant velvet ant has used reverse ssh tunnels to communicate to victim devices 19 mitigations id mitigation description m1037 filter network traffic use network appliances to filter ingress or egress traffic and perform protocol based filtering configure software on endpoints to filter network traffic m1031 network intrusion prevention network intrusion detection and prevention systems that use network signatures to identify traffic for specific adversary malware can be used to mitigate activity at the network level detection strategy id name analytic id analytic description det0444 detection of command and control over application layer protocols an1225 detects suspicious usage of common application layer protocols e g http https dns smb by abnormal processes with high outbound byte counts or irregular ports possibly indicating command and control or data exfiltration an1226 detects suspicious curl wget or custom socket traffic that leverages dns https or irc style protocols with unbalanced traffic or beacon like intervals an1227 detects applications using abnormal protocols or high volume traffic not previously associated with the process image such as automator or applescript invoking curl or python sockets an1228 detects application layer tunneling or unauthorized app protocols like dns over https embedded c2 in tls http headers or misused smb traffic crossing vlans references mandiant 2022 may 2 unc3524 eye spy on your email retrieved august 17 2023 lunghi d et al 2020 february uncovering drbcontrol retrieved november 12 2021 symantec security response 2011 november w32 duqu the precursor to the next stuxnet retrieved september 17 2015 mark graham carolyn ahlers kyle o meara dragos 2024 july impact of frostygoop ics malware on connected ot systems retrieved november 20 2024 chen j et al 2021 february 3 hildegard new teamtnt cryptojacking malware targeting kubernetes retrieved april 5 2021 team huntress 2023 august 11 investigating new inc ransom group activity retrieved june 5 2024 hsu k et al 2020 june 24 lucifer new cryptojacking and ddos hybrid malware exploiting high and critical vulnerabilities to infect windows devices retrieved november 16 2020 lee b and falcone r 2017 february 15 magic hound campaign attacks saudi targets retrieved december 27 2017 dfir report 2021 november 15 exchange exploit leads to domain wide ransomware retrieved january 5 2023 ahn ho facundo muñoz marc etienne m léveillé 2024 march 7 evasive panda leverages monlam festival to target tibetans retrieved july 25 2024 threat hunter team 2024 july 23 daggerfly espionage group makes major update to toolset retrieved july 25 2024 lauren podber and stef rand 2022 may 5 raspberry robin gets the worm early retrieved may 17 2024 christopher so 2022 december 20 raspberry robin malware targets telecom governments retrieved may 17 2024 patrick schläpfer 2024 april 10 raspberry robin now spreading through windows script files retrieved may 17 2024 liebenberg d 2018 august 30 rocke the champion of monero miners retrieved may 26 2020 prizmant d 2021 june 7 siloscape first known malware targeting windows containers to compromise cloud environments retrieved june 9 2021 cybereason global soc and incident response team n d sliver c2 leveraged by many threat actors retrieved march 24 2025 fiser d oliveira a n d tracking the activities of teamtnt a closer look at a cloud focused malicious actor group retrieved september 22 2021 sygnia team 2024 june 3 china nexus threat group velvet ant abuses f5 load balancers for persistence retrieved march 14 2025 core objects all core att ck objects all none matrices tactics techniques sub techniques defenses all defenses all none mitigations assets detection strategies analytics data components cti all cti all none groups software campaigns reference all reference all none resources domains all domains all none enterprise mobile ics reset filters contact us terms of use privacy policy website changelog cookie preferences 2015 2026 the mitre corporation mitre att ck and att ck are registered trademarks of the mitre corporation
Thumbnail images (randomly selected): * Images may be subject to copyright.GREEN status (no comments)
  • External site

Verified site has: 72 subpage(s). Do you want to verify them? Verify pages:

1-5 6-10 11-15 16-20 21-25 26-30 31-35 36-40 41-45 46-50
51-55 56-60 61-65 66-70 71-72


The site also has references to the 1 subdomain(s)

  mitre.org  Verify


Top 50 hastags from of all verified websites.

Supplementary Information (add-on for SEO geeks)*- See more on header.verify-www.com

Header

HTTP/1.1 301 Moved Permanently
Connection close
Content-Length 162
Server GitHub.com
Content-Type text/html
Location htt????/attack.mitre.org/techniques/T1071
X-GitHub-Request-Id 98A0:19A3F5:6AC835F:6BB39B0:6A8C3E27
x-github-edge-region fra
Accept-Ranges bytes
Age 0
Date Mon, 24 Aug 2026 12:50:47 GMT
Via 1.1 varnish
X-Served-By cache-rtm-ehrd2290047-RTM
X-Cache MISS
X-Cache-Hits 0
X-Timer S1787575847.460895,VS0,VE128
Vary Accept-Encoding
X-Fastly-Request-ID 6c0883e5e9921ab44b499efe9b9ec35a6746f718
HTTP/2 301
server GitHub.com
content-type text/html
x-origin-cache HIT
location htt????/attack.mitre.org/techniques/T1071/
access-control-allow-origin *
expires Mon, 24 Aug 2026 13:00:47 GMT
cache-control max-age=600
x-proxy-cache MISS
x-github-request-id 9A6C:15FA:17FA16F:183B973:6A8C3E26
x-github-edge-region fra
accept-ranges bytes
age 0
date Mon, 24 Aug 2026 12:50:47 GMT
via 1.1 varnish
x-served-by cache-rtm-ehrd2290048-RTM
x-cache MISS
x-cache-hits 0
x-timer S1787575848.629806,VS0,VE99
vary Accept-Encoding
x-fastly-request-id e715baf5975af68bce36671838e384139329e0c7
content-length 162
HTTP/2 200
server GitHub.com
content-type text/html; charset=utf-8
x-origin-cache HIT
last-modified Fri, 07 Aug 2026 14:24:18 GMT
access-control-allow-origin *
etag W/ 6a75ea92-109b7
expires Mon, 24 Aug 2026 13:00:47 GMT
cache-control max-age=600
content-encoding gzip
x-proxy-cache MISS
x-github-request-id 514E:81195:686AA09:6955BB4:6A8C3E27
x-github-edge-region fra
accept-ranges bytes
age 0
date Mon, 24 Aug 2026 12:50:47 GMT
via 1.1 varnish
x-served-by cache-rtm-ehrd2290048-RTM
x-cache MISS
x-cache-hits 0
x-timer S1787575848.744071,VS0,VE103
vary Accept-Encoding
x-fastly-request-id 38d0edbf695e1a697779905222a042d9413e656e
content-length 10941

Meta Tags

title="Application Layer Protocol, Technique T1071 - Enterprise | MITRE ATT&CK®"
name="google-site-verification" content="2oJKLqNN62z6AOCb0A0IXGtbQuj-lev5YPAHFF_cbHQ"
charset="utf-8"
name="viewport" content="width=device-width, initial-scale=1,shrink-to-fit=no"
http-equiv="X-UA-Compatible" content="IE=edge"

Load Info

page size10941
load time (s)0.680526
redirect count2
speed download16089
server IP 185.199.109.153
* all occurrences of the string "http://" have been changed to "htt???/"