T1573 Encrypted Channel — ATT&CK Technique
Adversaries may employ an encryption algorithm to conceal command and control traffic rather than relying on any inherent protections provided by a communication protocol. Despite the use of a secure algorithm, these implementations may be vulnerable to reverse engineering if secret keys are encoded and/or generated within malware samples/configuration files.
Detection coverage (8)
- Potential Pikabot C2 Activity high
- Kalambur Backdoor Curl TOR SOCKS Proxy Execution high
- Activity from Suspicious IP Addresses medium
- Activity from Anonymous IP Addresses medium
- Activity from Infrequent Country medium
- Suspicious SSL Connection low
- SSL Certificates with Punycode
- Zeek x509 Certificate with Punycode