Cross-source coverage
T1573 / ATT&CK
Encrypted Channel
41 rules · 39 families across 7 sources.
23 atomic-IOC hidden · include
Showing deprecated rules · back to the default
From MITRE ATT&CK 19.2
Adversaries may employ an encryption algorithm to conceal command and control traffic rather than relying on any inherent protections provided by a communication protocol. Despite the use of a secure algorithm, these implementations may be vulnerable to reverse engineering if secret keys are encoded and/or generated within malware samples/configuration files.
- Tactics
- Command and Control
- Platforms
- ESXi · Linux · macOS · Network Devices · Windows
- Telemetry
-
WinEventLog:Sysmonauditd:SYSCALLlinux:sysloglinux:osquerymacos:unifiedlogesxi:vpxdesxi:vmkernelNSM:FlowNSM:Connections
How MITRE says to detect it DET0273
Detection Strategy for Encrypted Channel across OS Platforms
Windows Analytic 0759
Processes that normally do not initiate network connections establishing outbound encrypted TLS/SSL sessions, especially with asymmetric traffic volumes (client sending more than receiving) or non-standard certificate chains. Defender observations correlate process creation with unexpected network encryption libraries being loaded.
WinEventLog:SysmonEventCode=3, 22WinEventLog:SysmonEventCode=7
Linux Analytic 0760
Processes like curl, wget, python, socat, or custom binaries initiating TLS/SSL sessions to non-standard destinations. Defender sees abnormal syscalls for connect(), loading of libssl libraries, and persistent outbound encrypted traffic from daemons not normally communicating externally.
auditd:SYSCALLsocket/connect with TLS context by unexpected processlinux:syslogsystem daemons initiating TLS sessions outside expected serviceslinux:osqueryProcesses linked with libssl or crypto libraries making outbound connections
macOS Analytic 0761
Applications or launchd jobs initiating encrypted TLS traffic to rare external hosts. Defender observes unified logs showing ssl/TLS API calls by processes not baseline-approved, and payload entropy suggesting encrypted C2 sessions.
macos:unifiedlogEncrypted session initiation by unexpected binarymacos:unifiedlogProcess invoking SSL routines from Security framework
ESXi Analytic 0762
VMware management daemons or guest processes initiating encrypted connections outside expected vCenter, update servers, or internal comms. Defender identifies hostd or vpxa initiating outbound TLS flows with uncommon destinations.
esxi:vpxdTLS session established by ESXi service to unapproved endpointesxi:vmkernelInspection of sockets showing encrypted sessions from non-baseline processes
Network Devices Analytic 0763
Unusual TLS tunnels through ports not normally encrypted (e.g., TLS on port 8080, 53). Defender sees NetFlow/IPFIX or packet inspection indicating high-entropy traffic volumes and asymmetric client/server exchange ratios.
NSM:FlowSession records with TLS-like byte patternsNSM:ConnectionsAbnormal certificate chains or non-standard ports carrying TLS
Sub-techniques with coverage
Counted in the 41 above — a rule tagged a sub-technique covers this technique too.
Emerging Threats Open
17 rules · 15 families| Detection | Severity | Format |
|---|---|---|
| ET DELETED Win32/XWorm CnC Activity (Inbound) | Critical | Suricata |
| ET DELETED Win32/XWorm CnC Activity (Outbound) | Critical | Suricata |
| ET MALWARE Winos4.0 Framework CnC Login Message CnC Server Response | Critical | Suricata |
| ET MALWARE Atemu RAT CnC Checkin Attempt | High | Suricata |
| ET MALWARE Atemu RAT Tasking Request | High | Suricata |
| ET MALWARE Atemu RAT User-Agent Observed (CommandExecutor/1.0) | High | Suricata |
| ET MALWARE Ave Maria/Warzone RAT Credential Exfil | High | Suricata |
| ET MALWARE Ave Maria/Warzone RAT Encrypted CnC Checkin | High | Suricata |
| ET MALWARE Ave Maria/Warzone RAT Encrypted CnC Checkin (Inbound) 2 variants | High | Suricata |
| ET MALWARE Ave Maria/Warzone RAT Encrypted CnC Checkin (Inbound) 2 variants | High | Suricata |
+ 7 more from Emerging Threats Open → showing the 10 highest-severity
splunk/security_content
7 rules| Detection | Severity | Format |
|---|---|---|
| Cisco Secure Firewall - Blacklisted SSL Certificate Fingerprint | Undefined | SPL |
| Cisco Secure Firewall - High EVE Threat Confidence | Undefined | SPL |
| Cisco Secure Firewall - Intrusion Events by Threat Activity | Undefined | SPL |
| Cisco Secure Firewall - Lumma Stealer Download Attempt | Undefined | SPL |
| Cisco Secure Firewall - Lumma Stealer Outbound Connection Attempt | Undefined | SPL |
| SSL Certificates with Punycode | Undefined | SPL |
| Zeek x509 Certificate with Punycode | Undefined | SPL |
SigmaHQ/sigma
6 rules| Detection | Severity | Format |
|---|---|---|
| Kalambur Backdoor Curl TOR SOCKS Proxy Execution | High | Sigma |
| Potential Pikabot C2 Activity | High | Sigma |
| Activity from Anonymous IP Addresses | Medium | Sigma |
| Activity from Infrequent Country | Medium | Sigma |
| Activity from Suspicious IP Addresses | Medium | Sigma |
| Suspicious SSL Connection | Low | Sigma |
elastic/detection-rules
6 rules| Detection | Severity | Format |
|---|---|---|
| Default Cobalt Strike Team Server Certificate | High | Elastic TOML |
| Deprecated TLS Version or Weak Cipher Negotiated Externally | Medium | Elastic TOML |
| Openssl Client or Server Activity | Medium | Elastic TOML |
| Connection to Commonly Abused Free SSL Certificate Providers | Low | Elastic TOML |
| Deprecated - Potential Non-Standard Port HTTP/HTTPS connection | Low | Elastic TOML |
| IPSEC NAT Traversal Port Activity | Low | Elastic TOML |
elastic/protections-artifacts
2 rules| Detection | Severity | Format |
|---|---|---|
| Potential Command and Control via Windows Scripts | Undefined | Elastic TOML |
| Suspicious Execution from a Windows Script | Undefined | Elastic TOML |
panther-labs/panther-analysis
2 rules| Detection | Severity | Format |
|---|---|---|
| GCP K8s IOCActivity | Medium | Panther Python |
| Kubernetes API Activity from Tor Exit Node | Medium | Panther Python |
Azure/Azure-Sentinel
1 rule| Detection | Severity | Format |
|---|---|---|
| First-Time Network Connection by Unusual Process | High | KQL |