Umbra Wiki technique technique/T1001.002
Back to wiki

T1001.002 — Steganography

provenance: imported · ATT&CK: T1001.002

T1001.002: Steganography

MITRE ATT&CK® Enterprise technique

Tactics Command And Control
Platforms Linux, macOS, Windows, ESXi
Permissions required
Version 1.1
Parent technique T1001

Description

Adversaries may use steganographic techniques to hide command and control traffic to make detection efforts more difficult. Steganographic techniques can be used to hide data in digital messages that are transferred between systems. This hidden information can be used for command and control of compromised systems. In some cases, the passing of files embedded using steganography, such as image or document files, can be used for command and control.

Detection

(no detection guidance published)

Data sources

  • (none listed)

References

  • ATT&CK page: https://attack.mitre.org/techniques/T1001/002
  • ATT&CK Enterprise matrix: https://attack.mitre.org/matrices/enterprise/