Cross-source coverage

T1079 / ATT&CK

Multilayer Encryption

ATT&CK has retired this technique. Rules still tag it; the current id is T1573 Encrypted Channel.

1 rule across 1 source.

Showing deprecated rules · back to the default

From MITRE ATT&CK 19.2

An adversary performs C2 communications using multiple layers of encryption, typically (but not exclusively) tunneling a custom encryption scheme within a protocol encryption scheme such as HTTPS or SMTPS.

Platforms
Linux · macOS · Windows
Telemetry

chronicle/detection-rules

1 rule
Detection Severity Format
suspicious_curl_usage Undefined YARA-L

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.