T1573.001SubTechniquecommand-and-controlagent-callable
T1573.001Symmetric Cryptography
Sub-technique of T1573
Platforms: Linux · Windows · macOS
ATT&CK version: 14.1
What it is
Adversaries may employ a known symmetric encryption algorithm to conceal command and control traffic rather than relying on any inherent protections provided by a communication protocol. Symmetric encryption algorithms use the same key for plaintext encryption and ciphertext decryption. Common symmetric encryption algorithms include AES, DES, 3DES, Blowfish, and RC4.