216.73.216.233

T1001: T1001

View on MITRE ATT&CK The MITRE Corporation · Published 31/05/2017 23:30 · Modified 03/04/2026 21:34

Essential information

MITRE technique ID
T1001
Confidence
100/100
Revoked
No
Published
31/05/2017 23:30
Modified
03/04/2026 21:34
Author / Source
The MITRE Corporation

Aliases

Data Obfuscation

Platforms

windows macos linux ESXi

Description

Adversaries may obfuscate command and control traffic to make it more difficult to detect.(Citation: Bitdefender FunnyDream Campaign November 2020) Command and control (C2) communications are hidden (but not necessarily encrypted) in an attempt to make the content more difficult to discover or decipher and to make the communication less conspicuous and hide commands from being seen. This encompasses many methods, such as adding junk data to protocol traffic, using steganography, or impersonating legitimate protocols.

Kill chain phases

Kill chainPhase
mitre-attack command-and-control

Marking (TLP)

TLP:CLEAR Copyright 2015-2025, The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation.

External references