{"id":"T1048.001","name":"Exfiltration Over Symmetric Encrypted Non-C2 Protocol","url":"https://attack.mitre.org/techniques/T1048/001","tactics":["exfiltration"],"platforms":["Linux","macOS","Windows","ESXi"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0503","stix_id":"x-mitre-detection-strategy--5d368ccf-2946-4a01-bfae-c18064b6187a","name":"Behavioral Detection Strategy for Exfiltration Over Symmetric Encrypted Non-C2 Protocol","url":"https://attack.mitre.org/detectionstrategies/DET0503","analytics":[{"id":"AN1389","stix_id":"x-mitre-analytic--4e5ffb58-75de-4305-a439-98ca3499f45e","name":"Analytic 1389","description":"Detects the execution of non-browser processes establishing outbound encrypted network connections using uncommon symmetric encryption protocols (e.g., AES via PowerShell or custom scripts) to alternate external destinations.","url":"https://attack.mitre.org/detectionstrategies/DET0503#AN1389","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=3, 22","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"PayloadEntropyThreshold","description":"Flag high-entropy payloads sent over unexpected protocols."},{"field":"TimeWindow","description":"Define allowable transfer window (e.g., abnormal traffic outside business hours)."},{"field":"ExecutableAllowlist","description":"List of known-good binaries for encrypted traffic (e.g., Chrome, Outlook)."}],"live":true,"detection_strategies":["DET0503"],"techniques":["T1048.001"]},{"id":"AN1390","stix_id":"x-mitre-analytic--d8978977-d2c8-4c1c-a6c1-0176330e3446","name":"Analytic 1390","description":"Detects command-line utilities or scripts using encryption libraries or symmetric algorithms (e.g., OpenSSL AES, GPG, Python + PyCrypto) in conjunction with outbound file transfers or traffic to external destinations.","url":"https://attack.mitre.org/detectionstrategies/DET0503#AN1390","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"},{"name":"auditd:SYSCALL","channel":"connect","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"auditd-syscall"},{"name":"NSM:Flow","channel":"conn.log or flow data","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"nsm-flow"},{"name":"NSM:Flow","channel":"ssl.log (for TLS handshake analysis), dns.log (tunneling indicators)","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"FileTransferIndicator","description":"Threshold for transferred data size or extension type."},{"field":"LibraryCallTracking","description":"Hooks into use of encryption libraries like `libcrypto.so`, `pycrypto`, `gpg`."}],"live":true,"detection_strategies":["DET0503"],"techniques":["T1048.001"]},{"id":"AN1391","stix_id":"x-mitre-analytic--bcab4073-2316-4685-be6c-fb5ab92b22be","name":"Analytic 1391","description":"Detects symmetric key-based encryption operations (e.g., AES via Python, AppleScript, or OpenSSL) followed by unusual outbound connections from non-browser applications or scripted tools.","url":"https://attack.mitre.org/detectionstrategies/DET0503#AN1391","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"log stream process subsystem","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"},{"name":"macos:osquery","channel":"socket_events","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"macos-osquery"},{"name":"macos:unifiedlog","channel":"log stream network activity","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"ApplicationProfileBaseline","description":"Expected outbound connection profiles per app."},{"field":"EncryptionRoutinePattern","description":"Indicators of manual encryption operations (e.g., script strings invoking AES)."}],"live":true,"detection_strategies":["DET0503"],"techniques":["T1048.001"]},{"id":"AN1392","stix_id":"x-mitre-analytic--d73a1356-7f4f-4f54-afca-437736e5f53c","name":"Analytic 1392","description":"Detects unexpected encrypted egress traffic from management services (e.g., hostd) or guest VMs utilizing symmetric encryption without traditional protocols (e.g., FTP with embedded AES ciphertext).","url":"https://attack.mitre.org/detectionstrategies/DET0503#AN1392","platforms":["ESXi"],"log_source_references":[{"name":"esxi:vmkernel","channel":"egress log analysis","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"esxi-vmkernel"},{"name":"esxi:hostd","channel":"execution + payload hints","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"esxi-hostd"},{"name":"NSM:Flow","channel":"host switch egress data","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"GuestVMExfilWatchlist","description":"VMs with data sensitivity labels or outside normal behavior."},{"field":"ServiceEgressProfile","description":"Expected egress destinations and volume for core services."}],"live":true,"detection_strategies":["DET0503"],"techniques":["T1048.001"]}],"live":true,"version":"1.0","techniques":["T1048.001"]}],"sigma_rules":[{"id":"98a96a5a-64a0-4c42-92c5-489da3866cb0","title":"DNS Exfiltration and Tunneling Tools Execution","author":"Daniil Yugoslavskiy, oscd.community","status":"test","level":"high","date":"2019-10-24","modified":"2021-11-27","description":"Well-known DNS Exfiltration tools execution","references":["https://github.com/iagox86/dnscat2","https://github.com/yarrick/iodine"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.exfiltration","attack.t1048.001","attack.command-and-control","attack.t1071.004","attack.t1132.001"],"path":"rules/windows/process_creation/proc_creation_win_dns_exfiltration_tools_execution.yml","techniques":["T1048.001","T1071.004","T1132.001"],"cves":[]}],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}