T1001Techniquecommand-and-controlagent-callable

T1001Data Obfuscation

Platforms: Linux · macOS · Windows

ATT&CK version: 14.1

What it is

Adversaries may obfuscate command and control traffic to make it more difficult to detect. Command and control (C2) communications are hidden (but not necessarily encrypted) in an attempt to make the content more difficult to discover or decipher and to make the communication less conspicuous and hide commands from being seen. This encompasses many methods, such as adding junk data to protocol traffic, using steganography, or impersonating legitimate protocols.

ATT&CK tactics· 1

Command And Control

References

  1. https://attack.mitre.org/techniques/T1001
  2. https://arxiv.org/ftp/arxiv/papers/1408/1408.1136.pdf
Sourced from MITRE ATT&CK Enterprise v14.1. Curated and contextualized for EU compliance use cases by Adam Lundqvist, Founder at SQUR.