Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Command and Control/ T1573

T1573Encrypted Channel

T1573 — Encrypted Channel is a MITRE ATT&CK technique in the Command and Control tactic. Clankerusecase tracks 10 detection use cases covering it and 9 threat-intel articles citing it.

Command and Control
View on the matrix → Filter Detection Library MITRE official spec ↗
10Use cases
9Articles
2Sub-techniques
1Tactic

Sub-techniques (2)

Use cases covering this technique (10)

SSL Certificates with Punycode ESCU actions · hunting P Zeek x509 Certificate with Punycode ESCU actions · hunting P [LLM] linuxFile backdoor WebSocket C2 to intel.se9ly9upbhay.shop and campaign C2 IPs Bespoke c2 · hunting DSΣPDDCS [LLM] Armored Likho Still Sync gRPC C2 beacon (tg4service.com / still.rpc.Sync) Bespoke c2 · alerting DSΣPDDCS [LLM] Hardcoded WebSocket backdoor to 154.92.19.71:39989 (no DNS) Bespoke c2 · hunting DSΣPDDCS [LLM] CornFlake C2 egress from masqueraded svchost32.exe in AppData Bespoke c2 · hunting DSΣPDDCS [LLM] Outbound C2 to PlugX/ShadowPad/Cobalt Strike/Remcos infrastructure targeting Pakistani law enforcement Bespoke c2 · alerting DSΣPDDCS [LLM] Compromised web-application server beaconing to espionage C2 (portal-update implant) Bespoke c2 · hunting DSΣPDDCS [LLM] Cross-platform stealer RAT C2 beacon to 23.254.164.123 Bespoke c2 · alerting DSPDDCS [LLM] HTTPS POST to /startlog with codexui User-Agent (Codex exfil over the wire) Bespoke actions · alerting DSΣPDDCS

Articles citing this technique (9)