T1573 — Encrypted Channel
T1573: Encrypted Channel
MITRE ATT&CK® Enterprise technique
| Tactics | Command And Control |
| Platforms | ESXi, Linux, macOS, Network Devices, Windows |
| Permissions required | — |
| Version | 1.2 |
Description
Adversaries may employ an encryption algorithm to conceal command and control traffic rather than relying on any inherent protections provided by a communication protocol. Despite the use of a secure algorithm, these implementations may be vulnerable to reverse engineering if secret keys are encoded and/or generated within malware samples/configuration files.
Detection
(no detection guidance published)
Data sources
- (none listed)
References
- ATT&CK page: https://attack.mitre.org/techniques/T1573
- ATT&CK Enterprise matrix: https://attack.mitre.org/matrices/enterprise/