Encrypted Channel T1573

Tactic: Command & Control

Adversaries may employ an encryption algorithm to conceal command and control traffic rather than relying on any inherent protections provided by a communication protocol. Despite the use of a secure algorithm, these implementations may be vulnerable to reverse engineering if secret keys are encoded and/or generated within malware samples/configuration files.

Events covered

5 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 28 rules share fields, values, and exclusions.

Fields filtered most (62 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
EventType10eq 9, in 1intrusionevent, start, connection_attempted, *, connectionevent
sourcetype6eq 6cisco:sfw:estreamer, zeek:x509:json
Protocol4eq 4tcp, udp
Image3ends_with 2, wildcard 1\curl.exe, \searchfilterhost.exe, \searchprotocolhost.exe, \sndvol.exe, c:\windows\explorer.exe
aws::eventName3eq 3activity from anonymous ip addresses, activity from infrequent country, activity from suspicious ip addresses
aws::eventSource3eq 3securitycompliancecenter
data_stream.dataset3eq 2, in 1network_traffic.tls, network_traffic.flow, zeek.connection
status3eq 3success
CommandLine2contains 2-encodedcommand, .onion, socks4a://, socks5://
DestinationPortName2eq 2dns, tls
Initiated2eq 2egress, true
SourcePort2eq 1, ge 14500, 49152
event.category2in 2network, network_traffic
host.os.type2eq 2
p_enrichment.tor_exit_nodes2is_not_null 2

Top indicator values (170 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
sourcetypeeq
cisco:sfw:estreamer
532
EventTypeeq
intrusionevent
318
EventTypeeq
connection_attempted
273
EventTypeeq
start
2391
Protocoleq
tcp
326
aws::eventSourceeq
securitycompliancecenter
314
statuseq
success
321
data_stream.dataseteq
network_traffic.tls
22
event.categoryin
network
218
event.categoryin
network_traffic
216
process.uptimege
300
22
src_ipin
10.0.0.0/8
216
src_ipin
172.16.0.0/12
216
src_ipin
192.168.0.0/16
216
CommandLinecontains
-encodedcommand
14
CommandLinecontains
.onion
1
CommandLinecontains
socks4a://
1
CommandLinecontains
socks5://
1
CommandLinecontains
socks5h://
1
DestinationPorteq
4500
1
DestinationPortNameeq
dns
15
DestinationPortNameeq
tls
1
DstPortNumberin
443
12
DstPortNumberin
80
1
DvcActioneq
allowed
18
EVE_ThreatConfidencePctge
80
1
EfectiveCommandregex_match
regexEmpire
1
EventCategoryeq
firewall
17
EventDatacontains
-encodedcommand
1
EventDatacontains
powershell.exe
1

Exclusions (80 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
dest_ipcidr_match
10.0.0.0/8
2
dest_ipcidr_match
100.64.0.0/10
2
dest_ipcidr_match
127.0.0.0/8
2
dest_ipcidr_match
169.254.0.0/16
2
dest_ipcidr_match
172.16.0.0/12
2
dest_ipcidr_match
192.0.0.0/24
2
dest_ipcidr_match
192.0.0.0/29
2
dest_ipcidr_match
192.0.0.10/32
2
dest_ipcidr_match
192.0.0.170/32
2
dest_ipcidr_match
192.0.0.171/32
2
dest_ipcidr_match
192.0.0.8/32
2
dest_ipcidr_match
192.0.0.9/32
2
dest_ipcidr_match
192.0.2.0/24
2
dest_ipcidr_match
192.175.48.0/24
2
dest_ipcidr_match
192.31.196.0/24
2

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 6 rules

Elastic 7 rules

Splunk 7 rules

Kusto 6 rules

Panther 2 rules