Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0273 — Detection Strategy for Encrypted Channel across OS Platforms
DET0273

Detection Strategy for Encrypted Channel across OS Platforms

5 analytic(s) · 1 technique(s) detected

Analytics

5
AN0759 Analytic 0759
Windows

Processes that normally do not initiate network connections establishing outbound encrypted TLS/SSL sessions, especially with asymmetric traffic volumes (client sending more than receiving) or non-standard certificate chains. Defender observations correlate process creation with unexpected network encryption libraries being loaded.

WinEventLog:Sysmon EventCode=3, 22 WinEventLog:Sysmon EventCode=7
[AllowedEncryptedProcesses] Whitelist processes expected to use TLS (e.g., browsers, mail clients).
[EntropyThreshold] Payload randomness threshold to distinguish C2 encryption from legitimate traffic.
[TimeWindow] Correlation window between process creation, module load, and encrypted connection.
AN0760 Analytic 0760
Linux

Processes like curl, wget, python, socat, or custom binaries initiating TLS/SSL sessions to non-standard destinations. Defender sees abnormal syscalls for connect(), loading of libssl libraries, and persistent outbound encrypted traffic from daemons not normally communicating externally.

auditd:SYSCALL socket/connect with TLS context by unexpected process linux:syslog system daemons initiating TLS sessions outside expected services linux:osquery Processes linked with libssl or crypto libraries making outbound connections
[WhitelistedDaemons] Legitimate system services expected to use TLS (e.g., package updates).
[CertificateAuthorities] Trusted CAs; flag self-signed or unrecognized certs.
AN0761 Analytic 0761
macOS

Applications or launchd jobs initiating encrypted TLS traffic to rare external hosts. Defender observes unified logs showing ssl/TLS API calls by processes not baseline-approved, and payload entropy suggesting encrypted C2 sessions.

macos:unifiedlog Encrypted session initiation by unexpected binary macos:unifiedlog Process invoking SSL routines from Security framework
[DoHResolvers] Known legitimate DoH endpoints to reduce false positives.
[PayloadEntropyThreshold] High-entropy traffic deviations used to detect concealed channels.
AN0762 Analytic 0762
ESXi

VMware management daemons or guest processes initiating encrypted connections outside expected vCenter, update servers, or internal comms. Defender identifies hostd or vpxa initiating outbound TLS flows with uncommon destinations.

esxi:vpxd TLS session established by ESXi service to unapproved endpoint esxi:vmkernel Inspection of sockets showing encrypted sessions from non-baseline processes
[AllowedMgmtHosts] Baseline approved endpoints for vCenter or update services.
AN0763 Analytic 0763
Network Devices

Unusual TLS tunnels through ports not normally encrypted (e.g., TLS on port 8080, 53). Defender sees NetFlow/IPFIX or packet inspection indicating high-entropy traffic volumes and asymmetric client/server exchange ratios.

NSM:Flow Session records with TLS-like byte patterns NSM:Connections Abnormal certificate chains or non-standard ports carrying TLS
[PortProfiles] Define expected TLS port usage to flag anomalies.
[TrafficAsymmetryRatio] Sent/received byte thresholds to catch hidden C2.

Detected Techniques

1

Command & Control (1)

Details

MITRE ID
DET0273
STIX ID
x-mitre-detection-strategy--08861418-398c-4972-8850-5e11f2d32944
Analytics
5
Techniques Detected
1
By Tactic
Command & Control
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.