Skip to content
Every technique
T1008No distinct observable

Fallback Channels

Command and ControlESXi, Linux, macOS, Windows

Where this stands

A reviewer read the telemetry and concluded there is nothing here to detect that a sibling technique does not already cover.

The only thing that makes a connection a fallback channel is what happened before it: MITRE's own technique text is 'adversaries may use fallback or alternate communication channels if the primary channel is compromised or inaccessible', and every analytic repeats the condition — AN1376 is 'connections on uncommon ports or protocols following C2 disruption or blocking', AN1377 is 'outbound connections... following known disruption or blocked traffic', AN1378 is 'fallback traffic... after primary channel inactivity'. That prior event is not in the matched record, so no single-event rule can distinguish T1008 from its siblings. […]

Covered instead by T1571, T1095, T1071.004.

What the technique is

Adversaries may use fallback or alternate communication channels if the primary channel is compromised or inaccessible in order to maintain reliable command and control and to avoid data transfer thresholds.

Read it on attack.mitre.org

What MITRE says you would watch

  • AN1376

    Establishing network connections on uncommon ports or protocols following C2 disruption or blocking. Often executed by processes that typically exhibit no network activity.

  • AN1377

    Creation of outbound connections on alternate ports or using covert transport (e.g., ICMP, DNS) from non-network-intensive processes, following known disruption or blocked traffic.

  • AN1378

    Outbound fallback traffic from low-profile or background launch agents using unusual protocols or destinations after primary channel inactivity.

Technique names and descriptions © MITRE ATT&CK®, CC BY 4.0. Not endorsed by MITRE.