kevmap

TechniquesT1573 › T1573.001

T1573.001 Symmetric Cryptography

command and control — ESXi, Linux, macOS, Network Devices, Windows · attack.mitre.org · JSON

1
MITRE detection strategy
5
analytics
0
Sigma rules tagged attack.t1573.001
3
KEV CVEs mapped here
<p>Adversaries may employ a known symmetric encryption algorithm to conceal command and control traffic rather than relying on any inherent protections provided by a communication protocol. Symmetric encryption algorithms use the same key for plaintext encryption and ciphertext decryption. Common symmetric encryption algorithms include AES, DES, 3DES, Blowfish, and RC4.</p>

KEV CVEs mapped to this technique · CTID Mappings Explorer

CVEVendor / productMapping typeStateAdded
CVE-2021-44077Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus secondary impact Mapped2021-12-01
CVE-2021-40449Microsoft Windows secondary impact Mapped2021-11-17
CVE-2021-40539Zoho ManageEngine secondary impact Mapped2021-11-03

Detection strategy · ATT&CK Enterprise v19.2

Sigma rules · SigmaHQ da9bb07d64, tag attack.t1573.001

No Sigma rule carries this tag. MITRE publishes a detection strategy above, so the behaviour is specified; what is missing is public detection content. 3 actively exploited CVEs map here.

Rules tagged at the parent level (attack.t1573) 6

These target the parent technique, not this sub-technique specifically. Listed for completeness, not counted as coverage.

Author: Austin Songer @austinsonger · 2021-08-23 (modified 2022-10-09) · logsource: product=m365 service=threat_management · 0f2468a2-5055-4212-a368-7321198ee706
Detects when a Microsoft Cloud App Security reported when an activity occurs from a location that wasn't recently or never visited by any user in the organization.
Techniques: T1573
Author: frack113 · 2022-01-23 · logsource: product=windows category=ps_script · 195626f3-5f1b-4403-93b7-e6cfd4d6a078
Adversaries may employ a known encryption algorithm to conceal command and control traffic rather than relying on any inherent protections provided by a communication protocol.
Techniques: T1573
Author: Austin Songer @austinsonger · 2021-08-23 (modified 2022-10-09) · logsource: product=m365 service=threat_detection · a3501e8e-af9e-43c6-8cd6-9360bdaae498
Detects when a Microsoft Cloud App Security reported users were active from an IP address identified as risky by Microsoft Threat Intelligence. These IP addresses are involved in malicious activities, such as Botnet C&C, and may indicate compromised account.
Techniques: T1573
Author: Andreas Braathen (mnemonic.io) · 2023-10-27 (modified 2024-01-26) · logsource: product=windows category=network_connection · cae6cee6-0244-44d2-84ed-e65f548eb7dc
Detects the execution of rundll32 that leads to an external network connection. The malware Pikabot has been seen to use this technique to initiate C2-communication through hard-coded Windows binaries.
Techniques: T1573
Author: Austin Songer @austinsonger · 2021-08-23 (modified 2022-10-09) · logsource: product=m365 service=threat_management · d8b0a4fe-07a8-41be-bd39-b14afa025d95
Detects when a Microsoft Cloud App Security reported when users were active from an IP address that has been identified as an anonymous proxy IP address.
Techniques: T1573
Author: Arda Buyukkaya (EclecticIQ) · 2025-02-11 · logsource: product=windows category=process_creation · e99375eb-3ee0-407a-9f90-79569cc6a01c
Detects the execution of the "curl.exe" command, referencing "SOCKS" and ".onion" domains, which could be indicative of Kalambur backdoor activity.