Umbra Wiki technique technique/T1573.001
Back to wiki

T1573.001 — Symmetric Cryptography

provenance: imported · ATT&CK: T1573.001

T1573.001: Symmetric Cryptography

MITRE ATT&CK® Enterprise technique

Tactics Command And Control
Platforms ESXi, Linux, macOS, Network Devices, Windows
Permissions required
Version 1.2
Parent technique T1573

Description

Adversaries may employ a known symmetric encryption algorithm to conceal command and control traffic rather than relying on any inherent protections provided by a communication protocol. Symmetric encryption algorithms use the same key for plaintext encryption and ciphertext decryption. Common symmetric encryption algorithms include AES, DES, 3DES, Blowfish, and RC4.

Detection

(no detection guidance published)

Data sources

  • (none listed)

References

  • ATT&CK page: https://attack.mitre.org/techniques/T1573/001
  • ATT&CK Enterprise matrix: https://attack.mitre.org/matrices/enterprise/