T1132.002 — Data Encoding: Non-Standard Encoding
Sub-technique of T1132 Data Encoding
Description
Adversaries may encode data with a non-standard data encoding system to make the content of command and control traffic more difficult to detect. Command and control (C2) information can be encoded using a non-standard data encoding system that diverges from existing protocol specifications. Non-standard data encoding schemes may be based on or related to standard data encoding schemes, such as a modified Base64 encoding for the message body of an HTTP request.
Detected by EasySIEM
This project's own SigmaHQ-derived detection pipeline tags every compiled rule with the ATT&CK technique(s) it maps to -- if a rule in your install covers this technique, its alerts show up automatically on your own EasySIEM Console's ATT&CK Reference page, no lookup needed. This page exists so a click from there always lands here on easysiem.com, not on attack.mitre.org.