{"id":"T1600","name":"Weaken Encryption","url":"https://attack.mitre.org/techniques/T1600","tactics":["defense-impairment"],"platforms":["Network Devices"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0339","stix_id":"x-mitre-detection-strategy--de98fda3-10f9-4013-a163-fb9b6c117a9b","name":"Detection Strategy for Weaken Encryption on Network Devices","url":"https://attack.mitre.org/detectionstrategies/DET0339","analytics":[{"id":"AN0961","stix_id":"x-mitre-analytic--b192336c-4a85-4322-9ae8-fd6eb6b7747b","name":"Analytic 0961","description":"Defenders may observe unauthorized modifications to encryption-related configuration files, firmware, or crypto modules on network devices. Suspicious patterns include changes to cipher suite configurations, unexpected firmware updates affecting crypto libraries, disabling of hardware cryptographic accelerators, or reductions in key length policies. Correlating configuration changes with anomalies in encrypted traffic characteristics (e.g., weaker ciphers or sudden plaintext transmission) strengthens detection.","url":"https://attack.mitre.org/detectionstrategies/DET0339#AN0961","platforms":["Network Devices"],"log_source_references":[{"name":"networkdevice:config","channel":"Configuration change events referencing encryption, TLS/SSL, or IPSec settings","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"networkdevice-config"},{"name":"NSM:Flow","channel":"Traffic patterns showing downgrade from strong encryption (AES-256) to weaker or plaintext protocols","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"nsm-flow"},{"name":"snmp:status","channel":"Status change in cryptographic hardware modules (enabled -> disabled)","data_component":"DC0016","data_component_name":"Module Load","log_source_slug":"snmp-status"}],"mutable_elements":[{"field":"CipherSuiteWhitelist","description":"List of approved encryption algorithms and key lengths; customizable to organizational policy."},{"field":"TimeWindow","description":"Correlation period between configuration changes and abnormal traffic; adjustable to reduce false positives."},{"field":"AuthorizedFirmwareSources","description":"Known trusted sources of firmware updates; deviations indicate possible compromise."},{"field":"TrafficEntropyThreshold","description":"Baseline entropy measurements of encrypted traffic; deviations may reveal weakening of encryption."}],"live":true,"detection_strategies":["DET0339"],"techniques":["T1600"]}],"live":true,"version":"1.0","techniques":["T1600"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}