T1001.003SubTechniquecommand-and-controlagent-callable

T1001.003Protocol Impersonation

Sub-technique of T1001

Platforms: Linux · Windows · macOS

ATT&CK version: 14.1

What it is

Adversaries may impersonate legitimate protocols or web service traffic to disguise command and control activity and thwart analysis efforts. By impersonating legitimate protocols or web services, adversaries can make their command and control traffic blend in with legitimate network traffic. Adversaries may impersonate a fake SSL/TLS handshake to make it look like subsequent traffic is SSL/TLS encrypted, potentially interfering with some security tooling, or to make the traffic look like it is related with a trusted entity.

ATT&CK tactics· 1

Command And Control

References

  1. https://attack.mitre.org/techniques/T1001/003
  2. https://arxiv.org/ftp/arxiv/papers/1408/1408.1136.pdf
Sourced from MITRE ATT&CK Enterprise v14.1. Curated and contextualized for EU compliance use cases by Adam Lundqvist, Founder at SQUR.