MITRE ATT&CK CoA - T1048 - Exfiltration Over Alternative Protocol
This playbook Remediates the Exfiltration Over Alternative Protocol technique using intelligence-driven Courses of Action (COA) defined by Palo Alto Networks Unit 42 team. ***Disclaimer: This playbook does not simulate an attack using the specified technique, but follows the steps to remediation as defined by Palo Alto Networks Unit 42 team’s Actionable Threat Objects and Mitigations (ATOMs). Techniques Handled: - T1048: Exfiltration Over Alternative Protocol Kill Chain phases: - Exfiltration MITRE ATT&CK Description: Adversaries may steal data by exfiltrating it over a different protocol than that of the existing command and control channel. The data may also be sent to an alternate network location from the main command and control server. Alternate protocols include FTP, SMTP, HTTP/S, DNS, SMB, or any other network protocol not being used as the main command and control channel. Different protocol channels could also include Web services such as cloud storage. Adversaries may also opt to encrypt and/or obfuscate these alternate channels. Exfiltration Over Alternative Protocol can be done using various common operating system utilities such as Net/SMB or FTP. Possible playbook uses: - The playbook can be used independently to handle and remediate the specific technique. - The playbook can be used as a part of the “Courses of Action - Defense Evasion” playbook to remediate techniques based on the kill chain phase. - The playbook can be used as a part of the “MITRE ATT&CK - Courses of Action” playbook, which can be triggered by different sources and accepts the technique MITRE ATT&CK ID as an input.
MITRE ATT&CK - Courses of Action · 8 tasks · 3 inputs · 1 output
Details
| ID | MITRE ATT&CK CoA - T1048 - Exfiltration Over Alternative Protocol |
|---|---|
| From Version | 6.5.0 |
| Tasks | 8 |
README
This playbook Remediates the Exfiltration Over Alternative Protocol technique using intelligence-driven Courses of Action (COA) defined by Palo Alto Networks Unit 42 team.
***Disclaimer: This playbook does not simulate an attack using the specified technique, but follows the steps to remediation as defined by Palo Alto Networks Unit 42 team’s Actionable Threat Objects and Mitigations (ATOMs).
Techniques Handled:
- T1048: Exfiltration Over Alternative Protocol
Kill Chain phases:
- Exfiltration
MITRE ATT&CK Description:
Adversaries may steal data by exfiltrating it over a different protocol than that of the existing command and control channel. The data may also be sent to an alternate network location from the main command and control server.
Alternate protocols include FTP, SMTP, HTTP/S, DNS, SMB, or any other network protocol not being used as the main command and control channel. Different protocol channels could also include Web services such as cloud storage. Adversaries may also opt to encrypt and/or obfuscate these alternate channels.
Exfiltration Over Alternative Protocol can be done using various common operating system utilities such as Net/SMB or FTP.
Possible playbook uses:
- The playbook can be used independently to handle and remediate the specific technique.
- The playbook can be used as a part of the “Courses of Action - Defense Evasion” playbook to remediate techniques based on the kill chain phase.
- The playbook can be used as a part of the “MITRE ATT&CK - Courses of Action” playbook, which can be triggered by different sources and accepts the technique MITRE ATT&CK ID as an input.
Dependencies
This playbook uses the following sub-playbooks, integrations, and scripts.
Sub-playbooks
- PAN-OS - Block all unknown and unauthorized applications
- PAN-OS - Enforce Anti-Spyware Best Practices Profile
Integrations
This playbook does not use any integrations.
Scripts
- SetGridField
- Set
Commands
This playbook does not use any commands.
Playbook Inputs
| Name | Description | Default Value | Required |
|---|---|---|---|
| pre_post | Rules location. Can be ‘pre-rulebase’ or ‘post-rulebase’. Mandatory for Panorama instances. | Optional | |
| device-group | The device group for which to return addresses (Panorama instances). | Optional | |
| tag | Tag for which to filter the rules. | Optional |
Playbook Outputs
| Path | Description | Type |
|---|---|---|
| Handled.Techniques | The techniques handled in this playbook | unknown |
Playbook Image

Inputs
pre_post— Rules location. Can be 'pre-rulebase' or 'post-rulebase'. Mandatory for Panorama instances.device-group— The device group for which to return addresses (Panorama instances).tag— Tag for which to filter the rules.
Outputs
Handled.Techniques— The techniques handled in this playbook
Flowchart
description: "This playbook Remediates the Exfiltration Over Alternative Protocol technique using intelligence-driven Courses of Action (COA) defined by Palo Alto Networks Unit 42 team.\n \n***Disclaimer: This playbook does not simulate an attack using the specified technique, but follows the steps to remediation as defined by Palo Alto Networks Unit 42 team’s Actionable Threat Objects and Mitigations (ATOMs).\nTechniques Handled:\n- T1048: Exfiltration Over Alternative Protocol\n\nKill Chain phases:\n- Exfiltration\n\nMITRE ATT&CK Description:\nAdversaries may steal data by exfiltrating it over a different protocol than that of the existing command and control channel. The data may also be sent to an alternate network location from the main command and control server.\nAlternate protocols include FTP, SMTP, HTTP/S, DNS, SMB, or any other network protocol not being used as the main command and control channel. Different protocol channels could also include Web services such as cloud storage. Adversaries may also opt to encrypt and/or obfuscate these alternate channels.\nExfiltration Over Alternative Protocol can be done using various common operating system utilities such as Net/SMB or FTP.\n\nPossible playbook uses:\n- The playbook can be used independently to handle and remediate the specific technique.\n- The playbook can be used as a part of the “Courses of Action - Defense Evasion” playbook to remediate techniques based on the kill chain phase.\n- The playbook can be used as a part of the “MITRE ATT&CK - Courses of Action” playbook, which can be triggered by different sources and accepts the technique MITRE ATT&CK ID as an input.\n" id: MITRE ATT&CK CoA - T1048 - Exfiltration Over Alternative Protocol inputs: - description: Rules location. Can be 'pre-rulebase' or 'post-rulebase'. Mandatory for Panorama instances. key: pre_post playbookInputQuery: required: false value: {} - description: The device group for which to return addresses (Panorama instances). key: device-group playbookInputQuery: required: false value: {} - description: Tag for which to filter the rules. key: tag playbookInputQuery: required: false value: {} name: MITRE ATT&CK CoA - T1048 - Exfiltration Over Alternative Protocol outputs: - contextPath: Handled.Techniques description: The techniques handled in this playbook type: unknown starttaskid: "0" tasks: "0": id: "0" ignoreworker: false nexttasks: '#none#': - "2" note: false quietmode: 0 separatecontext: false skipunavailable: false task: brand: "" id: 83f276e0-301c-491f-8fe7-a37b4c12ff1e iscommand: false name: "" version: -1 description: '' taskid: 83f276e0-301c-491f-8fe7-a37b4c12ff1e timertriggers: [] type: start view: |- { "position": { "x": 50, "y": 50 } } "2": id: "2" ignoreworker: false nexttasks: '#none#': - "12" note: false quietmode: 0 separatecontext: false skipunavailable: false task: brand: "" id: 6657022f-6727-47c0-8ada-aecb122ac788 iscommand: false name: Block all unknown and unauthorized applications type: title version: -1 description: '' taskid: 6657022f-6727-47c0-8ada-aecb122ac788 timertriggers: [] type: title view: |- { "position": { "x": 50, "y": 195 } } "5": id: "5" ignoreworker: false nexttasks: '#none#': - "13" note: false quietmode: 0 separatecontext: false skipunavailable: false task: brand: "" id: d033a119-18ee-474e-8293-c0e572d6fa18 iscommand: false name: Enable DNS Security in Anti-Spyware profile type: title version: -1 description: '' taskid: d033a119-18ee-474e-8293-c0e572d6fa18 timertriggers: [] type: title view: |- { "position": { "x": 50, "y": 515 } } "9": id: "9" ignoreworker: false note: false quietmode: 0 separatecontext: false skipunavailable: false task: brand: "" id: dce36dde-a1e2-41a9-8b30-fb2f7cb33b6b iscommand: false name: Done type: title version: -1 description: '' taskid: dce36dde-a1e2-41a9-8b30-fb2f7cb33b6b timertriggers: [] type: title view: |- { "position": { "x": 50, "y": 1190 } } "12": id: "12" ignoreworker: false loop: exitCondition: "" iscommand: false max: 100 wait: 1 nexttasks: '#none#': - "5" note: false quietmode: 0 scriptarguments: device-group: complex: root: inputs.device-group pre_post: complex: root: inputs.pre_post tag: complex: root: inputs.tag separatecontext: true skipunavailable: false task: brand: "" id: def6956e-7aae-40bd-8cc1-01839dfaa9a0 iscommand: false name: PAN-OS - Block all unknown and unauthorized applications playbookId: PAN-OS - Block all unknown and unauthorized applications type: playbook version: -1 description: '' taskid: def6956e-7aae-40bd-8cc1-01839dfaa9a0 timertriggers: [] type: playbook view: |- { "position": { "x": 50, "y": 340 } } "13": id: "13" ignoreworker: false loop: exitCondition: "" iscommand: false max: 100 wait: 1 nexttasks: '#none#': - "15" note: false quietmode: 0 scriptarguments: ApplyToRule: complex: root: inputs.ApplyToRule device-group: complex: root: inputs.device-group pre-post-rulebase: complex: root: inputs.pre_post rule_name: complex: root: inputs.rule_name tag: complex: root: inputs.tag separatecontext: true skipunavailable: false task: brand: "" description: | This playbook enforces the Anti-Spyware Best Practices Profile as defined by Palo Alto Networks BPA. The playbook performs the following tasks: - Check for DNS Security license (If license is not activated, the playbook refers users to their Palo Alto Networks account manager for further instructions). - Get the existing profile information. - Get the best practices profile information. - Check if the best practices profile set by Cortex XSOAR is enforced. (If not, the playbook allows the user to compare the existing profile with the best practices and decide on the action to take). - Create best practices profile. - Apply profile to policy rules on PAN-OS firewall or Panorama. id: 86508f7e-e836-49c9-8d59-1c5dca58e66b iscommand: false name: PAN-OS - Enforce Anti-Spyware Best Practices Profile playbookId: PAN-OS - Enforce Anti-Spyware Best Practices Profile type: playbook version: -1 taskid: 86508f7e-e836-49c9-8d59-1c5dca58e66b timertriggers: [] type: playbook view: |- { "position": { "x": 50, "y": 660 } } "15": id: "15" ignoreworker: false nexttasks: '#none#': - "16" note: false quietmode: 0 scriptarguments: append: simple: "true" key: simple: Handled.Techniques stringify: {} value: simple: T1048 separatecontext: false skipunavailable: false task: brand: "" description: Set a value in context under the key you entered. id: bb3482d0-08a3-47ac-8d28-a5dbeeb95306 iscommand: false name: Set technique handled script: Set type: regular version: -1 taskid: bb3482d0-08a3-47ac-8d28-a5dbeeb95306 timertriggers: [] type: regular view: |- { "position": { "x": 50, "y": 835 } } "16": continueonerror: true id: "16" ignoreworker: false nexttasks: '#none#': - "9" note: false quietmode: 0 scriptarguments: columns: simple: technique context_path: simple: Handled.Techniques grid_id: simple: handledtechniques keys: {} overwrite: {} sort_by: {} unpack_nested_elements: {} separatecontext: false skipunavailable: false task: brand: "" description: Creates a Grid table from items or key-value pairs. id: cd7b97c4-9499-449a-8360-0b2dd97069c2 iscommand: false name: Set grid field script: SetGridField type: regular version: -1 taskid: cd7b97c4-9499-449a-8360-0b2dd97069c2 timertriggers: [] type: regular view: |- { "position": { "x": 50, "y": 1020 } } version: -1 view: |- { "linkLabelsPosition": {}, "paper": { "dimensions": { "height": 1205, "width": 380, "x": 50, "y": 50 } } } tests: - No tests (auto formatted) fromversion: 6.5.0