Encrypted Channel T1573

Tactic: Command & Control

Adversaries may employ an encryption algorithm to conceal command and control traffic rather than relying on any inherent protections provided by a communication protocol. Despite the use of a secure algorithm, these implementations may be vulnerable to reverse engineering if secret keys are encoded and/or generated within malware samples/configuration files.

Events covered

5 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 29 rules share fields, values, and exclusions.

Fields filtered most (67 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
EventType11eq 9, in 1, is_null 1intrusionevent, start, connection_attempted, *, connectionevent
sourcetype6eq 6cisco:sfw:estreamer, zeek:x509:json
Protocol5eq 5tcp, udp
DestinationPortName3eq 3tls, dns
Image3ends_with 2, wildcard 1\curl.exe, \searchfilterhost.exe, \searchprotocolhost.exe, \sndvol.exe, c:\windows\explorer.exe
aws::eventName3eq 3activity from anonymous ip addresses, activity from infrequent country, activity from suspicious ip addresses
aws::eventSource3eq 3securitycompliancecenter
data_stream.dataset3eq 2, in 1, is_null 1, ne 1network_traffic.tls, network_traffic.flow, panw.panos, zeek.connection
src_ip3cidr_match 2, in 1, is_not_null 110.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16, 100.64.0.0/10
status3eq 3success
CommandLine2contains 2-encodedcommand, .onion, socks4a://, socks5://
Initiated2eq 2egress, true
SourcePort2eq 1, ge 14500, 49152
event.category2eq 1, in 1network, network_traffic
host.os.type2eq 2

Top indicator values (181 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
sourcetypeeq
cisco:sfw:estreamer
532
Protocoleq
tcp
427
EventTypeeq
intrusionevent
318
EventTypeeq
connection_attempted
275
EventTypeeq
start
2392
aws::eventSourceeq
securitycompliancecenter
314
statuseq
success
321
DestinationPortNameeq
tls
22
DestinationPortNameeq
dns
15
data_stream.dataseteq
network_traffic.tls
22
process.uptimege
300
22
src_ipcidr_match
10.0.0.0/8
211
src_ipcidr_match
172.16.0.0/12
211
src_ipcidr_match
192.168.0.0/16
211
tls.establishedeq
true
22
CommandLinecontains
-encodedcommand
14
CommandLinecontains
.onion
1
CommandLinecontains
socks4a://
1
CommandLinecontains
socks5://
1
CommandLinecontains
socks5h://
1
DestinationPorteq
4500
1
DstPortNumberin
443
12
DstPortNumberin
80
1
DvcActioneq
allowed
18
EVE_ThreatConfidencePctge
80
1
EfectiveCommandregex_match
regexEmpire
1
Esql.recentge
0
1
Esql.recentle
10
16
EventCategoryeq
firewall
17
EventDatacontains
-encodedcommand
1

Exclusions (87 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
dest_ipcidr_match
10.0.0.0/8
4
dest_ipcidr_match
100.64.0.0/10
4
dest_ipcidr_match
127.0.0.0/8
4
dest_ipcidr_match
169.254.0.0/16
4
dest_ipcidr_match
172.16.0.0/12
4
dest_ipcidr_match
192.0.0.0/24
4
dest_ipcidr_match
192.0.2.0/24
4
dest_ipcidr_match
192.175.48.0/24
4
dest_ipcidr_match
192.31.196.0/24
4
dest_ipcidr_match
192.52.193.0/24
4
dest_ipcidr_match
192.88.99.0/24
4
dest_ipcidr_match
198.18.0.0/15
4
dest_ipcidr_match
198.51.100.0/24
4
dest_ipcidr_match
203.0.113.0/24
4
dest_ipcidr_match
224.0.0.0/4
4

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 6 rules

Elastic 8 rules

Splunk 7 rules

Kusto 6 rules

Panther 2 rules