| ID | Name |
|---|---|
| ATAGS-T1183.001 | Standard Encoding |
| ATAGS-T1183.002 | Non-Standard Encoding |
Threat Actors may encode data with a non-standard data encoding system to make the content of command and control traffic more difficult to detect. Command and control (C2) information can be encoded using a non-standard data encoding system that diverges from existing protocol specifications. Non-standard data encoding schemes may be based on or related to standard data encoding schemes, such as a modified Base64 encoding for the message body of an HTTP request.
This type of attack technique cannot be easily mitigated with preventive controls since it is based on the abuse of system features.