Compliance Node Overview
MITRE ATT&CK T1095 (Non-Application Layer Protocol) is an Enterprise Command and Control technique. Adversaries may use an OSI non-application layer protocol for communication between host and C2 server or among infected hosts within a network. The list of possible protocols is extensive. Specific examples include use of network layer protocols, such as the Internet Control Message Protocol (ICMP), transport layer protocols, such as the User Datagram Protocol (UDP), session layer protocols, such as Socket Secure (SOCKS), as well as redirected/tunneled protocols, such as Serial over LAN (SOL). Affected platforms: Windows, Linux, macOS, Network. MITRE-documented mitigations include M1031 Network Intrusion Prevention, M1037 Filter Network Traffic, M1030 Network Segmentation. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-03, AC-04, CA-07, CM-02, CM-06, CM-07, SC-07, SI-03.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1095/
SHA-256 integrity: 365080b473863c797dd46dfa6d85e6ca4b48fb8c222d486faede386ac7abab77
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1095: Non-Application Layer Protocol (https://attack.mitre.org/techniques/T1095/)
- MITRE ATT&CK Tactic TA0011: Command and Control (https://attack.mitre.org/tactics/TA0011/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access