{"id":"T1573.001","name":"Symmetric Cryptography","url":"https://attack.mitre.org/techniques/T1573/001","tactics":["command-and-control"],"platforms":["ESXi","Linux","macOS","Network Devices","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0143","stix_id":"x-mitre-detection-strategy--32c549cd-a06b-41f2-8063-8937ba7feab6","name":"Detection Strategy for Encrypted Channel via Symmetric Cryptography across OS Platforms","url":"https://attack.mitre.org/detectionstrategies/DET0143","analytics":[{"id":"AN0400","stix_id":"x-mitre-analytic--704bd588-a82b-4139-92ef-6dc6a48581c8","name":"Analytic 0400","description":"Processes that typically do not perform cryptographic operations loading symmetric encryption libraries (e.g., bcryptprimitives.dll, aes.dll), then initiating outbound connections with high-entropy payloads. Defender correlates process creation, DLL load, and anomalous encrypted traffic patterns.","url":"https://attack.mitre.org/detectionstrategies/DET0143#AN0400","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=7","data_component":"DC0016","data_component_name":"Module Load","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=3, 22","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"AllowedCryptoProcesses","description":"Processes normally expected to use symmetric crypto (e.g., disk encryption, secure messaging)."},{"field":"EntropyThreshold","description":"Minimum payload entropy score for flagging unusual encrypted sessions."},{"field":"TimeWindow","description":"Correlation window between module load and encrypted connection creation."}],"live":true,"detection_strategies":["DET0143"],"techniques":["T1573.001"]},{"id":"AN0401","stix_id":"x-mitre-analytic--8c64bf26-bda2-47fc-867d-bcc6a51d57a7","name":"Analytic 0401","description":"Unexpected processes (e.g., bash, python, custom binaries) dynamically loading libcrypto or performing AES/RC4 encryption operations, then initiating outbound sessions with abnormal byte entropy or asymmetric traffic patterns.","url":"https://attack.mitre.org/detectionstrategies/DET0143#AN0401","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve or socket/connect system calls from processes using crypto libraries","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"},{"name":"linux:syslog","channel":"System daemons initiating encrypted sessions with unexpected destinations","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"linux-syslog"},{"name":"linux:osquery","channel":"Process linked with libcrypto.so making external connections","data_component":"DC0016","data_component_name":"Module Load","log_source_slug":"linux-osquery"}],"mutable_elements":[{"field":"TrustedCryptoLibs","description":"Baseline expected crypto libraries to suppress false positives."},{"field":"TrafficAsymmetryRatio","description":"Ratio of sent/received bytes indicating possible hidden C2."}],"live":true,"detection_strategies":["DET0143"],"techniques":["T1573.001"]},{"id":"AN0402","stix_id":"x-mitre-analytic--531ba452-e3b8-4064-be28-31ddd13b3478","name":"Analytic 0402","description":"Launchd jobs or user processes invoking symmetric crypto APIs from the Security framework and generating outbound connections carrying randomized payloads inconsistent with normal TLS patterns.","url":"https://attack.mitre.org/detectionstrategies/DET0143#AN0402","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"Process using AES/RC4 routines unexpectedly","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"Encrypted connection with anomalous payload entropy","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"DoHResolvers","description":"Legitimate DNS-over-HTTPS endpoints to avoid FP."},{"field":"PayloadEntropyThreshold","description":"Define entropy level at which traffic should be flagged."}],"live":true,"detection_strategies":["DET0143"],"techniques":["T1573.001"]},{"id":"AN0403","stix_id":"x-mitre-analytic--50102ced-9c8f-47e6-b438-63b2a7fe983d","name":"Analytic 0403","description":"ESXi daemons (hostd, vpxa) unexpectedly using symmetric encryption routines for external connections. Defender identifies logs of service traffic with encrypted payloads inconsistent with VMware management baselines.","url":"https://attack.mitre.org/detectionstrategies/DET0143#AN0403","platforms":["ESXi"],"log_source_references":[{"name":"esxi:vpxd","channel":"Symmetric crypto routines triggered for external session","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"esxi-vpxd"},{"name":"esxcli:network","channel":"Socket sessions with randomized payloads inconsistent with TLS","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"esxcli-network"}],"mutable_elements":[{"field":"AllowedMgmtHosts","description":"Baseline list of approved vCenter and update endpoints."}],"live":true,"detection_strategies":["DET0143"],"techniques":["T1573.001"]},{"id":"AN0404","stix_id":"x-mitre-analytic--94e5fd96-1fde-41fd-863d-6ef9cb8a3e1a","name":"Analytic 0404","description":"Flows showing encrypted payloads with high entropy not matching TLS handshake patterns, particularly when occurring on non-standard ports. Defender observes NetFlow/IPFIX byte distribution anomalies or IDS/IPS detecting symmetric encryption patterns without associated key exchange.","url":"https://attack.mitre.org/detectionstrategies/DET0143#AN0404","platforms":["Network Devices"],"log_source_references":[{"name":"NSM:Flow","channel":"Flow records with entropy signatures resembling symmetric encryption","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"nsm-flow"},{"name":"NSM:Connections","channel":"Symmetric encryption detected without TLS handshake sequence","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"nsm-connections"}],"mutable_elements":[{"field":"PortProfiles","description":"Baseline expected encryption by port/protocol."},{"field":"TrafficVolumeThreshold","description":"Volume thresholds for distinguishing benign VPN traffic from hidden C2."}],"live":true,"detection_strategies":["DET0143"],"techniques":["T1573.001"]}],"live":true,"version":"1.0","techniques":["T1573.001"]}],"sigma_rules":[],"kev_cves":[{"cveID":"CVE-2021-44077","state":"mapped","mapping_types":["secondary_impact"]},{"cveID":"CVE-2021-40449","state":"mapped","mapping_types":["secondary_impact"]},{"cveID":"CVE-2021-40539","state":"mapped","mapping_types":["secondary_impact"]}],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}