Over ICMP
MITRE ATT&CK™ - Exfiltration Over Alternative Protocol - Technique T1048
Last updated
MITRE ATT&CK™ - Exfiltration Over Alternative Protocol - Technique T1048
Last updated
The Internet Control Message Protocol ICMP. It is a network layer protocol used to handle error reporting.
On a high level, the ICMP packet's structure contains a Data section that can include strings or copies of other information, such as the IPv4 header, used for error messages. The following diagram shows the Data section, which is optional to use. We can leverage this section in order to exfiltrate datas.
We can, on linux targets, exfiltrate datas with the -p
options of the ping
command.
Note that the -p option is only available for Linux operating systems. We can confirm that by checking the ping's help manual page.