{"id":"T1001","name":"Data Obfuscation","url":"https://attack.mitre.org/techniques/T1001","tactics":["command-and-control"],"platforms":["ESXi","Linux","macOS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0053","stix_id":"x-mitre-detection-strategy--e17b2809-7534-4749-9bd8-95fdb24e4891","name":"Detect Obfuscated C2 via Network Traffic Analysis","url":"https://attack.mitre.org/detectionstrategies/DET0053","analytics":[{"id":"AN0144","stix_id":"x-mitre-analytic--79c7d394-e772-479c-acf9-ddd05b8a68b9","name":"Analytic 0144","description":"Detects excessive outbound traffic to remote host over HTTP(S) from uncommon or previously unseen processes.","url":"https://attack.mitre.org/detectionstrategies/DET0053#AN0144","platforms":["Windows"],"log_source_references":[{"name":"NSM:Flow","channel":"HTTP ","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"OutboundByteThreshold","description":"Defines threshold ratio of outbound to inbound bytes that signals possible obfuscation"},{"field":"ProcessAllowlist","description":"List of known legitimate network clients to exclude from anomaly checks"}],"live":true,"detection_strategies":["DET0053"],"techniques":["T1001"]},{"id":"AN0145","stix_id":"x-mitre-analytic--07deb060-c373-4059-b73b-736688a25c80","name":"Analytic 0145","description":"Identifies custom or previously unseen userland processes initiating high-volume HTTP connections with low response volume.","url":"https://attack.mitre.org/detectionstrategies/DET0053#AN0145","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"connect","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"auditd-syscall"}],"mutable_elements":[{"field":"UserProcessBaseline","description":"Defines what is considered abnormal for a user-initiated process context"}],"live":true,"detection_strategies":["DET0053"],"techniques":["T1001"]},{"id":"AN0146","stix_id":"x-mitre-analytic--dc87f086-1764-43c2-a7bf-1a5ba2ea8191","name":"Analytic 0146","description":"Flags unexpected user applications initiating long-lived HTTP(S) sessions with irregular traffic patterns.","url":"https://attack.mitre.org/detectionstrategies/DET0053#AN0146","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"network flow","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"process","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"SessionDuration","description":"Session length that exceeds average per-user expectations"}],"live":true,"detection_strategies":["DET0053"],"techniques":["T1001"]}],"live":true,"version":"1.0","techniques":["T1001"]}],"sigma_rules":[],"kev_cves":[{"cveID":"CVE-2025-31201","state":"stale","mapping_types":["secondary_impact"]},{"cveID":"CVE-2025-31200","state":"stale","mapping_types":["secondary_impact"]}],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}