Techniques › T1001
T1001 Data Obfuscation
command and control — ESXi, Linux, macOS, Windows · attack.mitre.org · JSON
1
MITRE detection strategy
3
analytics
0
Sigma rules tagged attack.t1001
2
KEV CVEs mapped here
<p>Adversaries may obfuscate command and control traffic to make it more difficult to detect. Command and control (C2) communications are hidden (but not necessarily encrypted) in an attempt to make the content more difficult to discover or decipher and to make the communication less conspicuous and hide commands from being seen. This encompasses many methods, such as adding junk data to protocol traffic, using steganography, or impersonating legitimate protocols.</p>
KEV CVEs mapped to this technique · CTID Mappings Explorer
| CVE | Vendor / product | Mapping type | State | Added |
|---|---|---|---|---|
| CVE-2025-31201 | Apple Multiple Products | secondary impact | Stale | 2025-04-17 |
| CVE-2025-31200 | Apple Multiple Products | secondary impact | Stale | 2025-04-17 |
Detection strategy · ATT&CK Enterprise v19.2
- DET0053 Detect Obfuscated C2 via Network Traffic Analysis v1.0
AN0144 WindowsDetects excessive outbound traffic to remote host over HTTP(S) from uncommon or previously unseen processes.Tunable:
OutboundByteThresholdProcessAllowlistAN0145 LinuxIdentifies custom or previously unseen userland processes initiating high-volume HTTP connections with low response volume.Tunable:UserProcessBaselineAN0146 macOSFlags unexpected user applications initiating long-lived HTTP(S) sessions with irregular traffic patterns.Tunable:SessionDuration
Sigma rules · SigmaHQ da9bb07d64, tag attack.t1001
No Sigma rule carries this tag. MITRE publishes a detection strategy above, so the behaviour is specified; what is missing is public detection content. 2 actively exploited CVEs map here.