Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Attack Patterns T1001.002 — Steganography
T1001.002

Steganography

Command & Control
TLP:CLEAR

Description

Adversaries may use steganographic techniques to hide command and control traffic to make detection efforts more difficult. Steganographic techniques can be used to hide data in digital messages that are transferred between systems. This hidden information can be used for command and control of compromised systems. In some cases, the passing of files embedded using steganography, such as image or document files, can be used for command and control.

MITRE ATT&CK Detection Strategies
1

DET0235 Detecting Steganographic Command and Control via File + Network Correlation
AN0652 Linux

Unusual use of steganographic or media processing binaries (e.g., `steghide`, `ffmpeg`, `imagemagick`) followed by outbound communication to external IPs with high data output and media MIME types.

auditd:SYSCALL NSM:Flow NSM:Flow
AN0654 ESXi

Suspicious modification of file artifacts (e.g., logs, ISO templates) on ESXi datastores, followed by beaconing or POST operations to external IPs potentially hiding payloads in file-like traffic.

esxi:vmkernel esxi:hostd NSM:Flow
AN0651 Windows

Detect the creation or modification of common media file formats (e.g., .jpg, .png, .wav) following suspicious process activity like compression or encryption, especially when paired with lateral movement or exfiltration behavior.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon NSM:Flow
+1 more analytics

Details

Platforms
Linux
Macos
Windows
Esxi
Added
May 2, 2026
Leaving Threaticon

This link opens an external site that isn't part of the platform.