T1573.001 — Symmetric Cryptography
T1573.001: Symmetric Cryptography
MITRE ATT&CK® Enterprise technique
| Tactics | Command And Control |
| Platforms | ESXi, Linux, macOS, Network Devices, Windows |
| Permissions required | — |
| Version | 1.2 |
| Parent technique | T1573 |
Description
Adversaries may employ a known symmetric encryption algorithm to conceal command and control traffic rather than relying on any inherent protections provided by a communication protocol. Symmetric encryption algorithms use the same key for plaintext encryption and ciphertext decryption. Common symmetric encryption algorithms include AES, DES, 3DES, Blowfish, and RC4.
Detection
(no detection guidance published)
Data sources
- (none listed)
References
- ATT&CK page: https://attack.mitre.org/techniques/T1573/001
- ATT&CK Enterprise matrix: https://attack.mitre.org/matrices/enterprise/