T1573 — Encrypted Channel

provenance: imported · ATT&CK: T1573

T1573: Encrypted Channel

MITRE ATT&CK® Enterprise technique

Tactics Command And Control
Platforms ESXi, Linux, macOS, Network Devices, Windows
Permissions required —
Version 1.2

Description

Adversaries may employ an encryption algorithm to conceal command and control traffic rather than relying on any inherent protections provided by a communication protocol. Despite the use of a secure algorithm, these implementations may be vulnerable to reverse engineering if secret keys are encoded and/or generated within malware samples/configuration files.

Detection

(no detection guidance published)

Data sources

  • (none listed)

References

  • ATT&CK page: https://attack.mitre.org/techniques/T1573
  • ATT&CK Enterprise matrix: https://attack.mitre.org/matrices/enterprise/

See all 697 pages under Attacker techniques (ATT&CK) →

Related pages