Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Attack Patterns T1001 — Data Obfuscation
T1001

Data Obfuscation

Command & Control
TLP:CLEAR

Description

Adversaries may obfuscate command and control traffic to make it more difficult to detect.(Citation: Bitdefender FunnyDream Campaign November 2020) Command and control (C2) communications are hidden (but not necessarily encrypted) in an attempt to make the content more difficult to discover or decipher and to make the communication less conspicuous and hide commands from being seen. This encompasses many methods, such as adding junk data to protocol traffic, using steganography, or impersonating legitimate protocols.

MITRE ATT&CK Detection Strategies
1

DET0053 Detect Obfuscated C2 via Network Traffic Analysis
AN0144 Windows

Detects excessive outbound traffic to remote host over HTTP(S) from uncommon or previously unseen processes.

NSM:Flow
AN0145 Linux

Identifies custom or previously unseen userland processes initiating high-volume HTTP connections with low response volume.

auditd:SYSCALL
AN0146 macOS

Flags unexpected user applications initiating long-lived HTTP(S) sessions with irregular traffic patterns.

macos:unifiedlog macos:unifiedlog

Details

Platforms
Esxi
Linux
Macos
Windows
Added
May 2, 2026
Leaving Threaticon

This link opens an external site that isn't part of the platform.