Fallback Channels
Where this stands
A reviewer read the telemetry and concluded there is nothing here to detect that a sibling technique does not already cover.
The only thing that makes a connection a fallback channel is what happened before it: MITRE's own technique text is 'adversaries may use fallback or alternate communication channels if the primary channel is compromised or inaccessible', and every analytic repeats the condition — AN1376 is 'connections on uncommon ports or protocols following C2 disruption or blocking', AN1377 is 'outbound connections... following known disruption or blocked traffic', AN1378 is 'fallback traffic... after primary channel inactivity'. That prior event is not in the matched record, so no single-event rule can distinguish T1008 from its siblings. […]
What the technique is
Adversaries may use fallback or alternate communication channels if the primary channel is compromised or inaccessible in order to maintain reliable command and control and to avoid data transfer thresholds.
Read it on attack.mitre.orgWhat MITRE says you would watch
- AN1376
Establishing network connections on uncommon ports or protocols following C2 disruption or blocking. Often executed by processes that typically exhibit no network activity.
- AN1377
Creation of outbound connections on alternate ports or using covert transport (e.g., ICMP, DNS) from non-network-intensive processes, following known disruption or blocked traffic.
- AN1378
Outbound fallback traffic from low-profile or background launch agents using unusual protocols or destinations after primary channel inactivity.
Technique names and descriptions © MITRE ATT&CK®, CC BY 4.0. Not endorsed by MITRE.