Applied Cybernetics Group
Threat intel → detection pipeline
Friday, September 18, 2026
Data as of 13:09 UTC
Technique
T1573
Tactics
Command and Control
MISP citations
1
KEV CVEs mapped
0
Community rules
6
thrunt rules
1
Upstream
https://attack.mitre.org/techniques/T1573

MITRE description

Adversaries may employ an encryption algorithm to conceal command and control traffic rather than relying on any inherent protections provided by a communication protocol. Despite the use of a secure algorithm, these implementations may be vulnerable to reverse engineering if secret keys are encoded and/or generated within malware samples/configuration files.

Citing MISP events

Detection coverage

thrunt rules

SigmaHQ community rules

Signal counts reflect the current corpus snapshot: MISP citations are regex-extracted from CIRCL OSINT event text and galaxy tags; KEV mappings come from MITRE CTID; community coverage is the SigmaHQ rule inventory (core, emerging-threats, threat-hunting collections) at release r2026-07-01. Rule bodies are not mirrored — links go upstream.