What MITRE ATT&CK T1048.002: Exfiltration Over Asymmetric Encrypted Non-C2 Protocol (Enterprise Tactic TA0010 - Exfiltration) requires
MITRE ATT&CK T1048.002 (Exfiltration Over Asymmetric Encrypted Non-C2 Protocol) is an Enterprise Exfiltration sub-technique of T1048 (Exfiltration Over Alternative Protocol). Adversaries may steal data by exfiltrating it over an asymmetrically encrypted network protocol other than that of the existing command and control channel. The data may also be sent to an alternate network location from the main command and control server. Asymmetric encryption algorithms are those that use different keys on each end of the channel. Also known as public-key cryptography, this requires pairs of cryptographic keys that can encrypt/decrypt data from the corresponding key. Affected platforms: Linux, macOS, Windows. MITRE-documented mitigations include M1031 Network Intrusion Prevention, M1030 Network Segmentation, M1037 Filter Network Traffic, M1057 Data Loss Prevention. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-04, AC-06, AC-16, AC-20, AC-23, CA-03.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1048/002/
SHA-256 integrity: e8c1b3a3d21e918dd28139d42a621080c97a39d4eea6c8b7c0d7c83fc5fb54f1
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1048.002: Exfiltration Over Asymmetric Encrypted Non-C2 Protocol (https://attack.mitre.org/techniques/T1048/002/)
- MITRE ATT&CK Tactic TA0010: Exfiltration (https://attack.mitre.org/tactics/TA0010/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/mitre-attack-t1048-002-exfiltration-over-asymmetric-encrypted-non-c2-protocol.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/mitre-attack-t1048-002-exfiltration-over-asymmetric-encrypted-non-c2-protocol.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/mitre-attack-t1048-002-exfiltration-over-asymmetric-encrypted-non-c2-protocol
- Back to registry: Browse all 10,085 compliance nodes