Cross-source coverage
T1079 / ATT&CK
Multilayer Encryption
ATT&CK has retired this technique. Rules still tag it; the current id is T1573 Encrypted Channel.
0 rules across 0 sources.
1 deprecated hidden · include
From MITRE ATT&CK 19.2
An adversary performs C2 communications using multiple layers of encryption, typically (but not exclusively) tunneling a custom encryption scheme within a protocol encryption scheme such as HTTPS or SMTPS.
- Tactics
- Command and Control
- Platforms
- Linux · macOS · Windows
- Telemetry
- —
No live rules cover this technique. 1 deprecated rule is hidden.