{"id":"T1001.002","name":"Steganography","url":"https://attack.mitre.org/techniques/T1001/002","tactics":["command-and-control"],"platforms":["Linux","macOS","Windows","ESXi"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0235","stix_id":"x-mitre-detection-strategy--0aa86929-f232-4fa7-bdc9-120f917a3509","name":"Detecting Steganographic Command and Control via File + Network Correlation","url":"https://attack.mitre.org/detectionstrategies/DET0235","analytics":[{"id":"AN0651","stix_id":"x-mitre-analytic--e7be37f1-88f9-45e3-91d0-1ff37bc94892","name":"Analytic 0651","description":"Detect the creation or modification of common media file formats (e.g., .jpg, .png, .wav) following suspicious process activity like compression or encryption, especially when paired with lateral movement or exfiltration behavior.","url":"https://attack.mitre.org/detectionstrategies/DET0235#AN0651","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=11","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=3, 22","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"wineventlog-sysmon"},{"name":"NSM:Flow","channel":"Session Transfer Content","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"FileExtensionFilter","description":"Allows tuning of monitored file types (e.g., .jpg, .png, .docx)."},{"field":"PayloadEntropyThreshold","description":"Threshold for flagging potential hidden data in outbound payloads."},{"field":"ExecutionToExfilTimeWindow","description":"Time window between media creation and network transmission."}],"live":true,"detection_strategies":["DET0235"],"techniques":["T1001.002"]},{"id":"AN0652","stix_id":"x-mitre-analytic--191d5ea7-ff08-4433-ba1b-1c0ed755ca67","name":"Analytic 0652","description":"Unusual use of steganographic or media processing binaries (e.g., `steghide`, `ffmpeg`, `imagemagick`) followed by outbound communication to external IPs with high data output and media MIME types.","url":"https://attack.mitre.org/detectionstrategies/DET0235#AN0652","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"},{"name":"NSM:Flow","channel":"Captured File Content","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"nsm-flow"},{"name":"NSM:Flow","channel":"Observed File Transfers","data_component":"DC0059","data_component_name":"File Metadata","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"ToolNameMatch","description":"Specify which binaries to monitor (e.g., steghide, outguess)."},{"field":"OutboundTrafficPattern","description":"Adjust based on known normal file upload services."}],"live":true,"detection_strategies":["DET0235"],"techniques":["T1001.002"]},{"id":"AN0653","stix_id":"x-mitre-analytic--eb6edb6d-9684-4ef7-96b2-13c087276d80","name":"Analytic 0653","description":"Abnormal usage of Preview, ImageMagick, or binary editors to alter images/documents, followed by exfiltration or outbound connections with mismatched file MIME types or payload structure.","url":"https://attack.mitre.org/detectionstrategies/DET0235#AN0653","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"File creation","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"macos-unifiedlog"},{"name":"macos:osquery","channel":"process_events","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-osquery"},{"name":"NSM:Flow","channel":"C2 exfiltration","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"ParentProcessBaseline","description":"Allow tuning based on expected apps calling image-editing tools."},{"field":"TimeDelta","description":"Gap between file manipulation and outbound connection."}],"live":true,"detection_strategies":["DET0235"],"techniques":["T1001.002"]},{"id":"AN0654","stix_id":"x-mitre-analytic--80caf81c-0714-4fa5-8b77-8e2144e316b9","name":"Analytic 0654","description":"Suspicious modification of file artifacts (e.g., logs, ISO templates) on ESXi datastores, followed by beaconing or POST operations to external IPs potentially hiding payloads in file-like traffic.","url":"https://attack.mitre.org/detectionstrategies/DET0235#AN0654","platforms":["ESXi"],"log_source_references":[{"name":"esxi:vmkernel","channel":"Storage access and file ops","data_component":"DC0059","data_component_name":"File Metadata","log_source_slug":"esxi-vmkernel"},{"name":"esxi:hostd","channel":"Service initiated connections","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"esxi-hostd"},{"name":"NSM:Flow","channel":"Transferred file observations","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"FilenamePattern","description":"Tune for likely stego file names (e.g., wallpaper.jpg, template.iso)."},{"field":"UnusualDestinationIP","description":"Destination outside vCenter management subnet."}],"live":true,"detection_strategies":["DET0235"],"techniques":["T1001.002"]}],"live":true,"version":"1.0","techniques":["T1001.002"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}