Cross-source coverage

T1573 / ATT&CK

Encrypted Channel

61 rules · 56 families across 7 sources.

3 deprecated hidden · include

Showing atomic-IOC rules · back to the default

From MITRE ATT&CK 19.2

Adversaries may employ an encryption algorithm to conceal command and control traffic rather than relying on any inherent protections provided by a communication protocol. Despite the use of a secure algorithm, these implementations may be vulnerable to reverse engineering if secret keys are encoded and/or generated within malware samples/configuration files.

Platforms
ESXi · Linux · macOS · Network Devices · Windows
Telemetry
WinEventLog:Sysmonauditd:SYSCALLlinux:sysloglinux:osquerymacos:unifiedlogesxi:vpxdesxi:vmkernelNSM:FlowNSM:Connections

How MITRE says to detect it DET0273

Detection Strategy for Encrypted Channel across OS Platforms

Windows Analytic 0759

Processes that normally do not initiate network connections establishing outbound encrypted TLS/SSL sessions, especially with asymmetric traffic volumes (client sending more than receiving) or non-standard certificate chains. Defender observations correlate process creation with unexpected network encryption libraries being loaded.

  • WinEventLog:Sysmon EventCode=3, 22
  • WinEventLog:Sysmon EventCode=7

Linux Analytic 0760

Processes like curl, wget, python, socat, or custom binaries initiating TLS/SSL sessions to non-standard destinations. Defender sees abnormal syscalls for connect(), loading of libssl libraries, and persistent outbound encrypted traffic from daemons not normally communicating externally.

  • auditd:SYSCALL socket/connect with TLS context by unexpected process
  • linux:syslog system daemons initiating TLS sessions outside expected services
  • linux:osquery Processes linked with libssl or crypto libraries making outbound connections

macOS Analytic 0761

Applications or launchd jobs initiating encrypted TLS traffic to rare external hosts. Defender observes unified logs showing ssl/TLS API calls by processes not baseline-approved, and payload entropy suggesting encrypted C2 sessions.

  • macos:unifiedlog Encrypted session initiation by unexpected binary
  • macos:unifiedlog Process invoking SSL routines from Security framework

ESXi Analytic 0762

VMware management daemons or guest processes initiating encrypted connections outside expected vCenter, update servers, or internal comms. Defender identifies hostd or vpxa initiating outbound TLS flows with uncommon destinations.

  • esxi:vpxd TLS session established by ESXi service to unapproved endpoint
  • esxi:vmkernel Inspection of sockets showing encrypted sessions from non-baseline processes

Network Devices Analytic 0763

Unusual TLS tunnels through ports not normally encrypted (e.g., TLS on port 8080, 53). Defender sees NetFlow/IPFIX or packet inspection indicating high-entropy traffic volumes and asymmetric client/server exchange ratios.

  • NSM:Flow Session records with TLS-like byte patterns
  • NSM:Connections Abnormal certificate chains or non-standard ports carrying TLS

Sub-techniques with coverage

Counted in the 61 above — a rule tagged a sub-technique covers this technique too.


Emerging Threats Open

38 rules · 33 families
Detection Severity Format
ET MALWARE Winos4.0 Framework CnC Login Message CnC Server Response Critical Suricata
ET MALWARE Atemu RAT CnC Checkin Attempt High Suricata
ET MALWARE Atemu RAT Tasking Request High Suricata
ET MALWARE Atemu RAT User-Agent Observed (CommandExecutor/1.0) High Suricata
ET MALWARE Ave Maria/Warzone RAT Credential Exfil High Suricata
ET MALWARE Ave Maria/Warzone RAT Encrypted CnC Checkin High Suricata
ET MALWARE Ave Maria/Warzone RAT Encrypted CnC Checkin (Inbound) 2 variants High Suricata
ET MALWARE Ave Maria/Warzone RAT Encrypted CnC Checkin (Inbound) 2 variants High Suricata
ET MALWARE LeakyStealer CnC Checkin High Suricata
ET MALWARE Observed Malicious SSL Cert Associated with PolarEdge Botnet M1 4 variants High Suricata

+ 28 more from Emerging Threats Open → showing the 10 highest-severity

splunk/security_content

7 rules
Detection Severity Format
Cisco Secure Firewall - Blacklisted SSL Certificate Fingerprint Undefined SPL
Cisco Secure Firewall - High EVE Threat Confidence Undefined SPL
Cisco Secure Firewall - Intrusion Events by Threat Activity Undefined SPL
Cisco Secure Firewall - Lumma Stealer Download Attempt Undefined SPL
Cisco Secure Firewall - Lumma Stealer Outbound Connection Attempt Undefined SPL
SSL Certificates with Punycode Undefined SPL
Zeek x509 Certificate with Punycode Undefined SPL

SigmaHQ/sigma

6 rules
Detection Severity Format
Kalambur Backdoor Curl TOR SOCKS Proxy Execution High Sigma
Potential Pikabot C2 Activity High Sigma
Activity from Anonymous IP Addresses Medium Sigma
Activity from Infrequent Country Medium Sigma
Activity from Suspicious IP Addresses Medium Sigma
Suspicious SSL Connection Low Sigma

elastic/detection-rules

5 rules
Detection Severity Format
Default Cobalt Strike Team Server Certificate High Elastic TOML
Deprecated TLS Version or Weak Cipher Negotiated Externally Medium Elastic TOML
Openssl Client or Server Activity Medium Elastic TOML
Connection to Commonly Abused Free SSL Certificate Providers Low Elastic TOML
IPSEC NAT Traversal Port Activity Low Elastic TOML

elastic/protections-artifacts

2 rules
Detection Severity Format
Potential Command and Control via Windows Scripts Undefined Elastic TOML
Suspicious Execution from a Windows Script Undefined Elastic TOML

panther-labs/panther-analysis

2 rules
Detection Severity Format
GCP K8s IOCActivity Medium Panther Python
Kubernetes API Activity from Tor Exit Node Medium Panther Python

Azure/Azure-Sentinel

1 rule
Detection Severity Format
First-Time Network Connection by Unusual Process High KQL

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.