Umbra Wiki technique technique/T1132.001
Back to wiki

T1132.001 — Standard Encoding

provenance: imported · ATT&CK: T1132.001

T1132.001: Standard Encoding

MITRE ATT&CK® Enterprise technique

Tactics Command And Control
Platforms ESXi, Linux, macOS, Windows
Permissions required
Version 1.1
Parent technique T1132

Description

Adversaries may encode data with a standard data encoding system to make the content of command and control traffic more difficult to detect. Command and control (C2) information can be encoded using a standard data encoding system that adheres to existing protocol specifications. Common data encoding schemes include ASCII, Unicode, hexadecimal, Base64, and MIME.(Citation: Wikipedia Binary-to-text Encoding)(Citation: Wikipedia Character Encoding) Some data encoding systems may also result in data compression, such as gzip.

Detection

(no detection guidance published)

Data sources

  • (none listed)

References

  • ATT&CK page: https://attack.mitre.org/techniques/T1132/001
  • ATT&CK Enterprise matrix: https://attack.mitre.org/matrices/enterprise/