Data Encoding T1132

Tactic: Command & Control

Adversaries may encode data to make the content of command and control traffic more difficult to detect. Command and control (C2) information can be encoded using a standard data encoding system. Use of data encoding may adhere to existing protocol specifications and includes use of ASCII, Unicode, Base64, MIME, or other binary-to-text and character encoding systems. Some data encoding systems may also result in data compression, such as gzip.

Events covered

5 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 15 rules share fields, values, and exclusions.

Fields filtered most (15 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
CommandLine5contains 2, regex_match 2, wildcard 1(?i)-encode, *exec(base64.b64decode*aW1wb3J0IHN5cztpbXBvcnQg*, ::decompress, frombase64string, gzipstream
EventID5eq 51, 4688, 4103, 4104
process_name4regex_match 2, in 1, wildcard 1(?i)certutil, base16, base32, base32hex, bash
EventType3eq 2, in 1exec, ProcessRollup2, exec_event, proxylogs
event.type3eq 2, in 1start, change, creation
Image2contains 1, ends_with 1, is_not_null 1\dnscat2, \iodine.exe
Type2eq 2
host.os.type2eq 2
Action1eq 1blocked
HttpUserAgentOriginal1contains 1windowspowershell
LogType1eq 1Agent Traffic Logs, agent traffic logs
ScriptBlockText1contains 1frombase64string, h4si, memorystream
TotalBlockedEvents1gt 115
file.Ext.header_bytes1starts_with 11F8B, 1F9D, 1FA0
process.code_signature.trusted1ne 1true

Top indicator values (77 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
CommandLineregex_match
(?i)-encode
22
EventIDeq
1
2241
EventIDeq
4688
2317
EventIDeq
4103
1105
EventIDeq
4104
1269
event.typeeq
start
21078
process_nameregex_match
(?i)certutil
24
Actioneq
blocked
1
CommandLinecontains
::decompress
1
CommandLinecontains
frombase64string
115
CommandLinecontains
gzipstream
1
CommandLinecontains
h4si
1
CommandLinecontains
memorystream
1
CommandLinewildcard
*exec(base64.b64decode*aW1wb3J0IHN5cztpbXBvcnQg*
1
EventTypeeq
exec
1576
EventTypeeq
proxylogs
120
EventTypein
ProcessRollup2
1117
EventTypein
exec
1201
EventTypein
exec_event
1149
EventTypein
executed
198
EventTypein
process_started
183
EventTypein
start
1163
HttpUserAgentOriginalcontains
windowspowershell
12
Imagecontains
\dnscat2
1
Imageends_with
\iodine.exe
1
LogTypeeq
Agent Traffic Logs
1
LogTypeeq
agent traffic logs
1
ScriptBlockTextcontains
frombase64string
14
ScriptBlockTextcontains
h4si
1
ScriptBlockTextcontains
memorystream
1

Exclusions (2 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
process.argsin
--help
1
process.argsin
--version
1

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 4 rules

Elastic 3 rules

Splunk 5 rules

Kusto 3 rules