Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Command and Control/ T1573

T1573Encrypted Channel

T1573 — Encrypted Channel is a MITRE ATT&CK technique in the Command and Control tactic. Clankerusecase tracks 6 detection use cases covering it and 5 threat-intel articles citing it.

Command and Control
View on the matrix → Filter Detection Library MITRE official spec ↗
6Use cases
5Articles
2Sub-techniques
1Tactic

Sub-techniques (2)

Use cases covering this technique (6)

SSL Certificates with Punycode ESCU actions · hunting P Zeek x509 Certificate with Punycode ESCU actions · hunting P [LLM] Outbound C2 to PlugX/ShadowPad/Cobalt Strike/Remcos infrastructure targeting Pakistani law enforcement Bespoke c2 · alerting DSΣPDDCS [LLM] Compromised web-application server beaconing to espionage C2 (portal-update implant) Bespoke c2 · hunting DSΣPDDCS [LLM] Cross-platform stealer RAT C2 beacon to 23.254.164.123 Bespoke c2 · alerting DSPDDCS [LLM] HTTPS POST to /startlog with codexui User-Agent (Codex exfil over the wire) Bespoke actions · alerting DSΣPDDCS

Articles citing this technique (5)