T1573 Encrypted Channel
Adversaries may employ an encryption algorithm to conceal command and control traffic rather than relying on any inherent protections provided by a communication protocol. Despite the use of a secure algorithm, these implementations may be vulnerable to reverse engineering if secret keys are encoded and/or generated within malware samples/configuration files.
Who uses it · with stories on Jábega
Sigma rules to hunt it
- Potential Pikabot C2 Activityhightest · windows
- Kalambur Backdoor Curl TOR SOCKS Proxy Executionhighexperimental · windows
- Activity from Anonymous IP Addressesmediumtest · m365
- Activity from Infrequent Countrymediumtest · m365
- Activity from Suspicious IP Addressesmediumtest · m365
Rules from SigmaHQ · Detection Rule License 1.1. Technique from MITRE ATT&CK®.