Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Attack Patterns T1001.001 — Junk Data
T1001.001

Junk Data

Command & Control
TLP:CLEAR

Description

Adversaries may add junk data to protocols used for command and control to make detection more difficult.(Citation: FireEye SUNBURST Backdoor December 2020) By adding random or meaningless data to the protocols used for command and control, adversaries can prevent trivial methods for decoding, deciphering, or otherwise analyzing the traffic. Examples may include appending/prepending data with junk characters or writing junk characters between significant characters.

MITRE ATT&CK Detection Strategies
1

DET0011 Detecting Junk Data in C2 Channels via Behavioral Analysis
AN0032 macOS

Previously unseen applications generating outbound connections with atypical data flow characteristics, such as excessive data with no return response.

macos:unifiedlog macos:osquery NSM:Flow
AN0030 Windows

Processes generating large outbound connections with disproportionate send/receive ratios, often to uncommon ports or hosts, potentially inserting meaningless data into protocol payloads.

WinEventLog:Sysmon WinEventLog:Sysmon NSM:Flow
AN0031 Linux

Outbound traffic with anomalous payload sizes and patterns from non-networking processes, often observed via packet inspection or connection logs.

auditd:SYSCALL NSM:Flow
+1 more analytics

Details

Platforms
Esxi
Linux
Macos
Windows
Added
May 2, 2026
Leaving Threaticon

This link opens an external site that isn't part of the platform.