Skip to content
← LibraryTechnique entry
T1071Command and Control

Application Layer Protocol

Use HTTP(S), DNS, etc. for C2.

§ Where this technique fits

T1071 is catalogued under the Command and Control tactic of the offensive-security kill-chain. It appears in 8 approved dossiers in the registry, typically at step 4.9 on average.

Authoritative reference: attack.mitre.org/techniques/T1071/.

§ Dossiers chaining this technique

§ What commonly comes next

  1. 01
    Scheduled Task Hijack
    W-SCHEDTASK-HIJACK · Persistence
    seen 2×
  2. 02
    Autodiscover Domain Hijack
    EX-AUTODISCOVER-LEAK · Credential Access
    seen 1×
  3. 03seen 1×
  4. 04
    Valid Accounts
    T1078 · Initial Access
    seen 1×
  5. 05
    scrcons.exe WMI Event Subscription
    LOL-SCRCONS · Persistence
    seen 1×