Applied Cybernetics Group
T1573 — Encrypted Channel
- Technique
T1573- Tactics
- Command and Control
- MISP citations
- 1
- KEV CVEs mapped
- 0
- Community rules
- 6
- thrunt rules
- 1
- Upstream
- https://attack.mitre.org/techniques/T1573
MITRE description
Adversaries may employ an encryption algorithm to conceal command and control traffic rather than relying on any inherent protections provided by a communication protocol. Despite the use of a secure algorithm, these implementations may be vulnerable to reverse engineering if secret keys are encoded and/or generated within malware samples/configuration files.
Citing MISP events
Detection coverage
thrunt rules
SigmaHQ community rules
- Potential Pikabot C2 Activity (emerging-threats)
- Kalambur Backdoor Curl TOR SOCKS Proxy Execution (emerging-threats)
- Activity from Suspicious IP Addresses (core)
- Activity from Anonymous IP Addresses (core)
- Activity from Infrequent Country (core)
- Suspicious SSL Connection (core)