T1573.001SubTechniquecommand-and-controlagent-callable

T1573.001Symmetric Cryptography

Sub-technique of T1573

Platforms: Linux · Windows · macOS

ATT&CK version: 14.1

What it is

Adversaries may employ a known symmetric encryption algorithm to conceal command and control traffic rather than relying on any inherent protections provided by a communication protocol. Symmetric encryption algorithms use the same key for plaintext encryption and ciphertext decryption. Common symmetric encryption algorithms include AES, DES, 3DES, Blowfish, and RC4.

ATT&CK tactics· 1

Command And Control

References

  1. https://attack.mitre.org/techniques/T1573/001
  2. https://arxiv.org/ftp/arxiv/papers/1408/1408.1136.pdf
Sourced from MITRE ATT&CK Enterprise v14.1. Curated and contextualized for EU compliance use cases by Adam Lundqvist, Founder at SQUR.