{"id":"T1048.002","name":"Exfiltration Over Asymmetric Encrypted Non-C2 Protocol","url":"https://attack.mitre.org/techniques/T1048/002","tactics":["exfiltration"],"platforms":["ESXi","Linux","macOS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0512","stix_id":"x-mitre-detection-strategy--d187b646-5fb3-4d65-a190-e25e2131f802","name":"Detection of Exfiltration Over Asymmetric Encrypted Non-C2 Protocol","url":"https://attack.mitre.org/detectionstrategies/DET0512","analytics":[{"id":"AN1413","stix_id":"x-mitre-analytic--6869578d-d3e8-4a3c-9717-0a188dc0bafe","name":"Analytic 1413","description":"Detects non-browser processes that establish encrypted outbound connections (e.g., TLS/SSL) to unfamiliar or atypical destinations for the host/user, following a data staging or compression event.","url":"https://attack.mitre.org/detectionstrategies/DET0512#AN1413","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=3, 22","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Security","channel":"EventCode=4663, 4670, 4656","data_component":"DC0055","data_component_name":"File Access","log_source_slug":"wineventlog-security"},{"name":"NSM:Flow","channel":"ssl.log - Certificate Analysis","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"TimeWindow","description":"Correlates file access, encryption, and network transmission within a timeframe (e.g., 5 minutes)."},{"field":"CertificateIssuerDenylist","description":"Blocks or flags untrusted certificate authorities in SSL/TLS handshakes."},{"field":"BinaryAllowlist","description":"Whitelist for known-good applications allowed to use encrypted outbound traffic."}],"live":true,"detection_strategies":["DET0512"],"techniques":["T1048.002"]},{"id":"AN1414","stix_id":"x-mitre-analytic--a2309590-988e-4116-85e6-59bfc5357726","name":"Analytic 1414","description":"Detects staged file access (e.g., archive or obfuscation), followed by an encrypted outbound connection (TLS/HTTPS) from unusual processes such as curl/wget, Python scripts, or custom binaries.","url":"https://attack.mitre.org/detectionstrategies/DET0512#AN1414","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"},{"name":"auditd:SYSCALL","channel":"connect","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"auditd-syscall"},{"name":"NSM:Flow","channel":"ssl.log, conn.log","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"nsm-flow"},{"name":"auditd:SYSCALL","channel":"open, read","data_component":"DC0055","data_component_name":"File Access","log_source_slug":"auditd-syscall"}],"mutable_elements":[{"field":"ConnectionDestinationScope","description":"Restrict outbound connections to non-corporate domains or IPs."},{"field":"FileAccessExtensionList","description":"List of extensions considered sensitive or exfil-worthy (e.g., .zip, .db, .xlsx)."},{"field":"SSLClientProcessBaseline","description":"Define normal encrypted-traffic-capable binaries."}],"live":true,"detection_strategies":["DET0512"],"techniques":["T1048.002"]},{"id":"AN1415","stix_id":"x-mitre-analytic--46585379-5be9-4ce0-9178-c3492f539e11","name":"Analytic 1415","description":"Detects abnormal encrypted network connections (via TLS/HTTPS) initiated by non-browser binaries, particularly after sensitive file access or compression events.","url":"https://attack.mitre.org/detectionstrategies/DET0512#AN1415","platforms":["macOS"],"log_source_references":[{"name":"macos:osquery","channel":"socket_events","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"macos-osquery"},{"name":"macos:osquery","channel":"process_events","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-osquery"},{"name":"macos:unifiedlog","channel":"log stream - file provider subsystem","data_component":"DC0055","data_component_name":"File Access","log_source_slug":"macos-unifiedlog"},{"name":"NSM:Flow","channel":"ssl.log, x509.log","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"OutboundTrafficVolumeThreshold","description":"Trigger detection for large amounts of outbound encrypted data."},{"field":"FileSensitivityContext","description":"Tagging and prioritizing high-value directories/files in detection logic."}],"live":true,"detection_strategies":["DET0512"],"techniques":["T1048.002"]},{"id":"AN1416","stix_id":"x-mitre-analytic--20ecf7be-864a-4ae0-be66-cf26ffa9a217","name":"Analytic 1416","description":"Detects unexpected encrypted outbound connections from management components or guest VMs using TLS, particularly after data volume spikes or script-based orchestration from within guest environments.","url":"https://attack.mitre.org/detectionstrategies/DET0512#AN1416","platforms":["ESXi"],"log_source_references":[{"name":"esxi:hostd","channel":"event stream","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"esxi-hostd"},{"name":"esxi:vmkernel","channel":"egress logs","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"esxi-vmkernel"}],"mutable_elements":[{"field":"VMToEgressPathWatchlist","description":"Expected traffic routes for monitored VMs."},{"field":"TLSClientAppIdentifier","description":"Applications allowed to initiate TLS sessions from hypervisor level."}],"live":true,"detection_strategies":["DET0512"],"techniques":["T1048.002"]}],"live":true,"version":"1.0","techniques":["T1048.002"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}