Umbra Wiki technique technique/T1573
Back to wiki

T1573 — Encrypted Channel

provenance: imported · ATT&CK: T1573

T1573: Encrypted Channel

MITRE ATT&CK® Enterprise technique

Tactics Command And Control
Platforms ESXi, Linux, macOS, Network Devices, Windows
Permissions required
Version 1.2

Description

Adversaries may employ an encryption algorithm to conceal command and control traffic rather than relying on any inherent protections provided by a communication protocol. Despite the use of a secure algorithm, these implementations may be vulnerable to reverse engineering if secret keys are encoded and/or generated within malware samples/configuration files.

Detection

(no detection guidance published)

Data sources

  • (none listed)

References

  • ATT&CK page: https://attack.mitre.org/techniques/T1573
  • ATT&CK Enterprise matrix: https://attack.mitre.org/matrices/enterprise/