{"id":"T1573","name":"Encrypted Channel","url":"https://attack.mitre.org/techniques/T1573","tactics":["command-and-control"],"platforms":["ESXi","Linux","macOS","Network Devices","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0273","stix_id":"x-mitre-detection-strategy--08861418-398c-4972-8850-5e11f2d32944","name":"Detection Strategy for Encrypted Channel across OS Platforms","url":"https://attack.mitre.org/detectionstrategies/DET0273","analytics":[{"id":"AN0759","stix_id":"x-mitre-analytic--81233639-a08b-4a56-a5d4-ac2f9ae94a2b","name":"Analytic 0759","description":"Processes that normally do not initiate network connections establishing outbound encrypted TLS/SSL sessions, especially with asymmetric traffic volumes (client sending more than receiving) or non-standard certificate chains. Defender observations correlate process creation with unexpected network encryption libraries being loaded.","url":"https://attack.mitre.org/detectionstrategies/DET0273#AN0759","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=3, 22","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=7","data_component":"DC0016","data_component_name":"Module Load","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"AllowedEncryptedProcesses","description":"Whitelist processes expected to use TLS (e.g., browsers, mail clients)."},{"field":"EntropyThreshold","description":"Payload randomness threshold to distinguish C2 encryption from legitimate traffic."},{"field":"TimeWindow","description":"Correlation window between process creation, module load, and encrypted connection."}],"live":true,"detection_strategies":["DET0273"],"techniques":["T1573"]},{"id":"AN0760","stix_id":"x-mitre-analytic--f0dacfba-bcc0-43cb-bad5-0cd3fe3a7f5f","name":"Analytic 0760","description":"Processes like curl, wget, python, socat, or custom binaries initiating TLS/SSL sessions to non-standard destinations. Defender sees abnormal syscalls for connect(), loading of libssl libraries, and persistent outbound encrypted traffic from daemons not normally communicating externally.","url":"https://attack.mitre.org/detectionstrategies/DET0273#AN0760","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"socket/connect with TLS context by unexpected process","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"auditd-syscall"},{"name":"linux:syslog","channel":"system daemons initiating TLS sessions outside expected services","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"linux-syslog"},{"name":"linux:osquery","channel":"Processes linked with libssl or crypto libraries making outbound connections","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"linux-osquery"}],"mutable_elements":[{"field":"WhitelistedDaemons","description":"Legitimate system services expected to use TLS (e.g., package updates)."},{"field":"CertificateAuthorities","description":"Trusted CAs; flag self-signed or unrecognized certs."}],"live":true,"detection_strategies":["DET0273"],"techniques":["T1573"]},{"id":"AN0761","stix_id":"x-mitre-analytic--80c5c2fd-eb3a-4678-9d3b-6147a90284de","name":"Analytic 0761","description":"Applications or launchd jobs initiating encrypted TLS traffic to rare external hosts. Defender observes unified logs showing ssl/TLS API calls by processes not baseline-approved, and payload entropy suggesting encrypted C2 sessions.","url":"https://attack.mitre.org/detectionstrategies/DET0273#AN0761","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"Encrypted session initiation by unexpected binary","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"Process invoking SSL routines from Security framework","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"DoHResolvers","description":"Known legitimate DoH endpoints to reduce false positives."},{"field":"PayloadEntropyThreshold","description":"High-entropy traffic deviations used to detect concealed channels."}],"live":true,"detection_strategies":["DET0273"],"techniques":["T1573"]},{"id":"AN0762","stix_id":"x-mitre-analytic--b94bb114-7532-4934-9955-9c7031109b9e","name":"Analytic 0762","description":"VMware management daemons or guest processes initiating encrypted connections outside expected vCenter, update servers, or internal comms. Defender identifies hostd or vpxa initiating outbound TLS flows with uncommon destinations.","url":"https://attack.mitre.org/detectionstrategies/DET0273#AN0762","platforms":["ESXi"],"log_source_references":[{"name":"esxi:vpxd","channel":"TLS session established by ESXi service to unapproved endpoint","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"esxi-vpxd"},{"name":"esxi:vmkernel","channel":"Inspection of sockets showing encrypted sessions from non-baseline processes","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"esxi-vmkernel"}],"mutable_elements":[{"field":"AllowedMgmtHosts","description":"Baseline approved endpoints for vCenter or update services."}],"live":true,"detection_strategies":["DET0273"],"techniques":["T1573"]},{"id":"AN0763","stix_id":"x-mitre-analytic--29a00bef-79bd-4eb9-bf92-01651cffe9b0","name":"Analytic 0763","description":"Unusual TLS tunnels through ports not normally encrypted (e.g., TLS on port 8080, 53). Defender sees NetFlow/IPFIX or packet inspection indicating high-entropy traffic volumes and asymmetric client/server exchange ratios.","url":"https://attack.mitre.org/detectionstrategies/DET0273#AN0763","platforms":["Network Devices"],"log_source_references":[{"name":"NSM:Flow","channel":"Session records with TLS-like byte patterns","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"nsm-flow"},{"name":"NSM:Connections","channel":"Abnormal certificate chains or non-standard ports carrying TLS","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"nsm-connections"}],"mutable_elements":[{"field":"PortProfiles","description":"Define expected TLS port usage to flag anomalies."},{"field":"TrafficAsymmetryRatio","description":"Sent/received byte thresholds to catch hidden C2."}],"live":true,"detection_strategies":["DET0273"],"techniques":["T1573"]}],"live":true,"version":"1.0","techniques":["T1573"]}],"sigma_rules":[{"id":"0f2468a2-5055-4212-a368-7321198ee706","title":"Activity from Infrequent Country","author":"Austin Songer @austinsonger","status":"test","level":"medium","date":"2021-08-23","modified":"2022-10-09","description":"Detects when a Microsoft Cloud App Security reported when an activity occurs from a location that wasn't recently or never visited by any user in the organization.","references":["https://learn.microsoft.com/en-us/defender-cloud-apps/anomaly-detection-policy","https://learn.microsoft.com/en-us/defender-cloud-apps/policy-template-reference"],"logsource":{"product":"m365","service":"threat_management"},"tags":["attack.command-and-control","attack.t1573"],"path":"rules/cloud/m365/threat_management/microsoft365_activity_from_infrequent_country.yml","techniques":["T1573"],"cves":[]},{"id":"195626f3-5f1b-4403-93b7-e6cfd4d6a078","title":"Suspicious SSL Connection","author":"frack113","status":"test","level":"low","date":"2022-01-23","modified":null,"description":"Adversaries may employ a known encryption algorithm to conceal command and control traffic rather than relying on any inherent protections provided by a communication protocol.","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1573/T1573.md#atomic-test-1---openssl-c2","https://medium.com/walmartglobaltech/openssl-server-reverse-shell-from-windows-client-aee2dbfa0926"],"logsource":{"product":"windows","category":"ps_script"},"tags":["attack.command-and-control","attack.t1573"],"path":"rules/windows/powershell/powershell_script/posh_ps_susp_ssl_keyword.yml","techniques":["T1573"],"cves":[]},{"id":"a3501e8e-af9e-43c6-8cd6-9360bdaae498","title":"Activity from Suspicious IP Addresses","author":"Austin Songer @austinsonger","status":"test","level":"medium","date":"2021-08-23","modified":"2022-10-09","description":"Detects when a Microsoft Cloud App Security reported users were active from an IP address identified as risky by Microsoft Threat Intelligence.\nThese IP addresses are involved in malicious activities, such as Botnet C&C, and may indicate compromised account.\n","references":["https://learn.microsoft.com/en-us/defender-cloud-apps/anomaly-detection-policy","https://learn.microsoft.com/en-us/defender-cloud-apps/policy-template-reference"],"logsource":{"product":"m365","service":"threat_detection"},"tags":["attack.command-and-control","attack.t1573"],"path":"rules/cloud/m365/threat_detection/microsoft365_from_susp_ip_addresses.yml","techniques":["T1573"],"cves":[]},{"id":"cae6cee6-0244-44d2-84ed-e65f548eb7dc","title":"Potential Pikabot C2 Activity","author":"Andreas Braathen (mnemonic.io)","status":"test","level":"high","date":"2023-10-27","modified":"2024-01-26","description":"Detects the execution of rundll32 that leads to an external network connection.\nThe malware Pikabot has been seen to use this technique to initiate C2-communication through hard-coded Windows binaries.\n","references":["https://www.virustotal.com/gui/file/d72af640b71b8e3eca3eba660dd7c7f029ff8852bcacaa379e7b6c57cf4d9b44","https://www.virustotal.com/gui/file/6bb4cdbaef03b732a93559a58173e7f16b29bfb159a1065fae9185000ff23b4b","https://github.com/pr0xylife/Pikabot/blob/7f7723a74ca325ec54c6e61e076acce9a4b20538/Pikabot_06.12.2023.txt"],"logsource":{"product":"windows","category":"network_connection"},"tags":["attack.command-and-control","attack.t1573","detection.emerging-threats"],"path":"rules-emerging-threats/2023/Malware/Pikabot/net_connection_win_malware_pikabot_rundll32_activity.yml","techniques":["T1573"],"cves":[]},{"id":"d8b0a4fe-07a8-41be-bd39-b14afa025d95","title":"Activity from Anonymous IP Addresses","author":"Austin Songer @austinsonger","status":"test","level":"medium","date":"2021-08-23","modified":"2022-10-09","description":"Detects when a Microsoft Cloud App Security reported when users were active from an IP address that has been identified as an anonymous proxy IP address.","references":["https://learn.microsoft.com/en-us/defender-cloud-apps/anomaly-detection-policy","https://learn.microsoft.com/en-us/defender-cloud-apps/policy-template-reference"],"logsource":{"product":"m365","service":"threat_management"},"tags":["attack.command-and-control","attack.t1573"],"path":"rules/cloud/m365/threat_management/microsoft365_activity_from_anonymous_ip_addresses.yml","techniques":["T1573"],"cves":[]},{"id":"e99375eb-3ee0-407a-9f90-79569cc6a01c","title":"Kalambur Backdoor Curl TOR SOCKS Proxy Execution","author":"Arda Buyukkaya (EclecticIQ)","status":"experimental","level":"high","date":"2025-02-11","modified":null,"description":"Detects the execution of the \"curl.exe\" command, referencing \"SOCKS\" and \".onion\" domains, which could be indicative of Kalambur backdoor activity.","references":["https://blog.eclecticiq.com/sandworm-apt-targets-ukrainian-users-with-trojanized-microsoft-kms-activation-tools-in-cyber-espionage-campaigns"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.command-and-control","attack.t1090","attack.t1573","attack.t1071.001","attack.t1059.001","attack.s0183","detection.emerging-threats"],"path":"rules-emerging-threats/2025/Malware/proc_creation_win_malware_kalambur_curl_socks_tor.yml","techniques":["T1090","T1573","T1071.001","T1059.001"],"cves":[]}],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}