1200KM / simulation
T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol — Attack Simulation
Adversaries may steal data by exfiltrating it over an asymmetrically encrypted network protocol other than that of the existing command and control channel. The data may also be sent to an alternate network location from the main command and control server. Asymmetric encryption algorithms are those that use different keys on each end of the channel. Also known as public-key cryptography, this requires pairs of cryptographic keys that can…
Technique description
Adversaries may steal data by exfiltrating it over an asymmetrically encrypted network protocol other than that of the existing command and control channel. The data may also be sent to an alternate network location from the main command and control server. Asymmetric encryption algorithms are those that use different keys on each end of the channel. Also known as public-key cryptography, this requires pairs of cryptographic keys that can…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Exfiltrate data HTTPS using curl windows
Procedure 1cdf2fb0-51b6-4fd8-96af-77020d5f1bf0; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Exfiltrate data HTTPS using curl freebsd,linux or macos
Procedure 4a4f31e2-46ea-4c26-ad89-f09ad1d5fe01; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Exfiltrate data in a file over HTTPS using wget
Procedure 7ccdfcfa-6707-46bc-b812-007ab6ff951c; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Exfiltrate data as text over HTTPS using wget
Procedure 8bec51da-7a6d-4346-b941-51eca448c4b0; elevation not declared required; cleanup not declared. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.