{"id":"T1573.002","name":"Asymmetric Cryptography","url":"https://attack.mitre.org/techniques/T1573/002","tactics":["command-and-control"],"platforms":["ESXi","Linux","macOS","Network Devices","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0543","stix_id":"x-mitre-detection-strategy--e5448ab8-39d6-4364-ae7f-0459687251f7","name":"Detection Strategy for Encrypted Channel via Asymmetric Cryptography across OS Platforms","url":"https://attack.mitre.org/detectionstrategies/DET0543","analytics":[{"id":"AN1496","stix_id":"x-mitre-analytic--7e1c7338-11d5-4ab4-aefc-bbd81e26068d","name":"Analytic 1496","description":"Processes not typically associated with encryption loading asymmetric crypto libraries (e.g., rsaenh.dll, crypt32.dll) and subsequently initiating outbound TLS/SSL connections with abnormal certificate chains or handshakes. Defender correlates process creation, module load, and unusual encrypted sessions.","url":"https://attack.mitre.org/detectionstrategies/DET0543#AN1496","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=7","data_component":"DC0016","data_component_name":"Module Load","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=3, 22","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"AllowedCryptoProcesses","description":"Whitelist browsers, mail clients, or apps expected to use asymmetric crypto."},{"field":"CertificateAuthorityList","description":"Baseline CA list for validating abnormal certs."},{"field":"HandshakeTimeout","description":"Detection of incomplete or malformed handshakes."}],"live":true,"detection_strategies":["DET0543"],"techniques":["T1573.002"]},{"id":"AN1497","stix_id":"x-mitre-analytic--284edcb8-0141-4fe6-afb2-9fd8a2b82b49","name":"Analytic 1497","description":"Processes (e.g., bash, python, custom binaries) dynamically linking libcrypto/libssl for RSA key exchange, then creating external connections with abnormal certificate validation or handshake anomalies. Defender observes syscall traces and outbound asymmetric key exchanges from non-SSL-native processes.","url":"https://attack.mitre.org/detectionstrategies/DET0543#AN1497","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve or socket/connect system calls for processes using RSA handshake","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"},{"name":"linux:syslog","channel":"Non-standard processes negotiating SSL/TLS key exchanges","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"linux-syslog"},{"name":"linux:osquery","channel":"Processes linked with libssl/libcrypto performing network activity","data_component":"DC0016","data_component_name":"Module Load","log_source_slug":"linux-osquery"}],"mutable_elements":[{"field":"ExpectedCryptoLibs","description":"Baseline libraries that normally handle asymmetric crypto."},{"field":"TrafficAsymmetryRatio","description":"Threshold for client-heavy data sending vs server."}],"live":true,"detection_strategies":["DET0543"],"techniques":["T1573.002"]},{"id":"AN1498","stix_id":"x-mitre-analytic--6b63caad-5d8d-4f23-be77-4e81d8904da6","name":"Analytic 1498","description":"Applications or launchd services invoking RSA or public-key routines from the Security framework, followed by outbound SSL/TLS sessions with unrecognized certs or anomalous handshakes. Defender observes unified logs of API calls and suspicious network entropy.","url":"https://attack.mitre.org/detectionstrategies/DET0543#AN1498","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"Process invoking SecKeyCreateRandomKey or asymmetric crypto APIs","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"TLS connections with abnormal handshake sequence or self-signed cert","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"TrustedDoHEndpoints","description":"Known legitimate DoH/SSL endpoints."},{"field":"PayloadEntropyThreshold","description":"Entropy scoring for outbound payloads."}],"live":true,"detection_strategies":["DET0543"],"techniques":["T1573.002"]},{"id":"AN1499","stix_id":"x-mitre-analytic--0f9943f2-0e7e-44da-b7dd-e1a7cd52aae0","name":"Analytic 1499","description":"VMware services (hostd, vpxa) unexpectedly negotiating asymmetric crypto sessions to external endpoints outside vCenter or update servers. Defender sees encrypted handshakes in logs inconsistent with baseline ESXi communication patterns.","url":"https://attack.mitre.org/detectionstrategies/DET0543#AN1499","platforms":["ESXi"],"log_source_references":[{"name":"esxi:vpxd","channel":"ESXi process initiating asymmetric handshake with external host","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"esxi-vpxd"},{"name":"esxcli:network","channel":"Socket inspection showing RSA key exchange outside baseline endpoints","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"esxcli-network"}],"mutable_elements":[{"field":"BaselineMgmtHosts","description":"Expected external endpoints (vCenter, update repos)."}],"live":true,"detection_strategies":["DET0543"],"techniques":["T1573.002"]},{"id":"AN1500","stix_id":"x-mitre-analytic--3e5930bf-6d79-4f75-9b9e-97cad9bf9232","name":"Analytic 1500","description":"Encrypted sessions detected with asymmetric key exchange anomalies on non-standard ports or with invalid/malformed certs. Defender correlates NetFlow/IPFIX with IDS/IPS detecting RSA exchanges outside expected TLS flows.","url":"https://attack.mitre.org/detectionstrategies/DET0543#AN1500","platforms":["Network Devices"],"log_source_references":[{"name":"NSM:Flow","channel":"Flow records with RSA key exchange on unexpected port","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"nsm-flow"},{"name":"IDS:TLSInspection","channel":"Malformed certs, incomplete asymmetric handshakes, or invalid CAs","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"ids-tlsinspection"}],"mutable_elements":[{"field":"PortProfiles","description":"Define expected ports for asymmetric cryptography (e.g., 443, 993)."},{"field":"CertValidationPolicy","description":"Thresholds for rejecting untrusted/self-signed certs."}],"live":true,"detection_strategies":["DET0543"],"techniques":["T1573.002"]}],"live":true,"version":"1.0","techniques":["T1573.002"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}