Umbra Wiki technique technique/T1132.002
Back to wiki

T1132.002 — Non-Standard Encoding

provenance: imported · ATT&CK: T1132.002

T1132.002: Non-Standard Encoding

MITRE ATT&CK® Enterprise technique

Tactics Command And Control
Platforms ESXi, Linux, macOS, Windows
Permissions required
Version 1.1
Parent technique T1132

Description

Adversaries may encode data with a non-standard data encoding system to make the content of command and control traffic more difficult to detect. Command and control (C2) information can be encoded using a non-standard data encoding system that diverges from existing protocol specifications. Non-standard data encoding schemes may be based on or related to standard data encoding schemes, such as a modified Base64 encoding for the message body of an HTTP request.(Citation: Wikipedia Binary-to-text Encoding)(Citation: Wikipedia Character Encoding)

Detection

(no detection guidance published)

Data sources

  • (none listed)

References

  • ATT&CK page: https://attack.mitre.org/techniques/T1132/002
  • ATT&CK Enterprise matrix: https://attack.mitre.org/matrices/enterprise/