Skip to content
Every technique
T1665No distinct observable

Hide Infrastructure

Command and ControlESXi, Linux, macOS, Network Devices, Windows

Where this stands

A reviewer read the telemetry and concluded there is nothing here to detect that a sibling technique does not already cover.

No log source in the brief can carry the behaviour, and in each of the three analytics the part that separates hiding infrastructure from ordinary administration is a value list the brief supplies no values for — in two cases against a field the named log source does not have. AN1148 (Windows, Security 5156/5157) asks for DNS resolutions to short-lived domains, abnormal WHOIS registration data and user-agent anomalies, but 5156 and 5157 are Windows Filtering Platform connection records whose fields are Application, Direction, SourceAddress, SourcePort, DestAddress, DestPort, Protocol, FilterRTID and LayerName: there is no domain, no WHOIS and no user-agent anywhere in the event, so two of the three things the analytic describes cannot be selected on at all. […]

Covered instead by T1090, T1090.003, T1568, T1568.002, T1686 (was T1562.004).

What the technique is

Adversaries may manipulate network traffic in order to hide and evade detection of their C2 infrastructure. This can be accomplished by identifying and filtering traffic from defensive tools, masking malicious domains to obfuscate the true destination from both automated scanning tools and security researchers, and otherwise hiding malicious artifacts to delay discovery and prolong the effectiveness of adversary infrastructure that could otherwise be identified, blocked, or taken down entirely. C2 networks may include the use of Proxy or VPNs to disguise IP addresses, which can allow adversaries to blend in with normal network traffic and bypass conditional access policies or anti-abuse protections. For example, an adversary may use a virtual private cloud to spoof their IP address to closer align with a victim's IP address ranges. This may also bypass security measures relying on geolocation of the source IP address. Adversaries may also attempt to filter network traffic in order to evade defensive tools in numerous ways, including blocking/redirecting common incident responder or security appliance user agents. Filtering traffic based on IP and geo-fencing may also avoid automated sandboxing or researcher activity (i.e., Virtualization/Sandbox Evasion). […]

Read it on attack.mitre.org

What MITRE says you would watch

  • AN1148

    Monitor DNS queries, proxy logs, and user-agent strings for anomalous patterns associated with adversary attempts to hide infrastructure. Defenders may observe DNS resolutions to short-lived domains, abnormal WHOIS registration data, or filtering of known defensive/responder IP addresses.

  • AN1149

    Detect adversaries filtering traffic or modifying server responses to evade scanning. Monitor iptables, nftables, or proxy configurations that deny or redirect requests from known scanning agents or defensive tools.

  • AN1150

    Monitor unified logs for manipulation of proxy configurations, DNS resolution, or filtering rules. Adversaries may redirect responses or use trusted domains that later resolve to malicious C2 infrastructure.

Technique names and descriptions © MITRE ATT&CK®, CC BY 4.0. Not endorsed by MITRE.