Skip to content

DET0700 Detection of Bidirectional Communication

Item Value
ID DET0700
Version 1.0
Created 21 October 2025
Last Modified 21 October 2025

Technique Detected: T1481.002 (Bidirectional Communication)

Analytics

Android

AN1816

Application vetting services may provide a list of connections made or received by an application, or a list of domains contacted by the application. Many properly configured firewalls may naturally block bidirectional command and control traffic.

Log Sources
Data Component Name Channel
Network Communication (DC0113) Application Vetting None
Network Connection Creation (DC0082) Network Traffic None
Mutable Elements
Field Description

iOS

AN1817

Application vetting services may provide a list of connections made or received by an application, or a list of domains contacted by the application. Many properly configured firewalls may naturally block bidirectional command and control traffic.

Log Sources
Data Component Name Channel
Network Communication (DC0113) Application Vetting None
Network Connection Creation (DC0082) Network Traffic None
Mutable Elements
Field Description