What MITRE ATT&CK T1048.001: Exfiltration Over Symmetric Encrypted Non-C2 Protocol (Enterprise Tactic TA0010 - Exfiltration) requires
MITRE ATT&CK T1048.001 (Exfiltration Over Symmetric Encrypted Non-C2 Protocol) is an Enterprise Exfiltration sub-technique of T1048 (Exfiltration Over Alternative Protocol). Adversaries may steal data by exfiltrating it over a symmetrically encrypted network protocol other than that of the existing command and control channel. The data may also be sent to an alternate network location from the main command and control server. Symmetric encryption algorithms are those that use shared or the same keys/secrets on each end of the channel. This requires an exchange or pre-arranged agreement/possession of the value used to encrypt and decrypt data. Affected platforms: Linux, macOS, Windows. MITRE-documented mitigations include M1037 Filter Network Traffic, M1031 Network Intrusion Prevention, M1030 Network Segmentation. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-04, AC-06, AC-16, AC-20, AC-23, CA-03.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1048/001/
SHA-256 integrity: 2d7d970388ee4dfe891a3b5ed33e6fdecc354a770fc23a9da9e3705e63bdc5bf
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1048.001: Exfiltration Over Symmetric Encrypted Non-C2 Protocol (https://attack.mitre.org/techniques/T1048/001/)
- MITRE ATT&CK Tactic TA0010: Exfiltration (https://attack.mitre.org/tactics/TA0010/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/mitre-attack-t1048-001-exfiltration-over-symmetric-encrypted-non-c2-protocol.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/mitre-attack-t1048-001-exfiltration-over-symmetric-encrypted-non-c2-protocol.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/mitre-attack-t1048-001-exfiltration-over-symmetric-encrypted-non-c2-protocol
- Back to registry: Browse all 10,085 compliance nodes