FORENSIA

ATT&CK · T1001

Data Obfuscation

Tactics: command-and-control

About

Adversaries may obfuscate command and control traffic to make it more difficult to detect. Command and control (C2) communications are hidden (but not necessarily encrypted) in an attempt to make the content more difficult to discover or decipher and to make the communication less conspicuous and hide commands from being seen. This encompasses many methods, such as adding junk data to protocol traffic, using steganography, or impersonating legitimate protocols.

Platforms: ESXi, Linux, macOS, WindowsMITRE ATT&CK ↗

Used by actors

1 known groups

Software

13 malware/tools implement this

FlawedAmmyyOkrumRDATSLOTHFULMEDIASideTwistTrailBlazerFunnyDreamNinjaDarkGateFRAMESTINGStrelaStealerSystemBCevilginx2

Corpus indicators tagged with this technique

10 indicators in the corpus carry T1001.