Skip to content

DET0641 Detection of Encrypted Channel

Item Value
ID DET0641
Version 1.0
Created 21 October 2025
Last Modified 21 October 2025

Technique Detected: T1521 (Encrypted Channel)

Analytics

Android

AN1716

Since data encryption is a common practice in many legitimate applications and uses standard programming language-specific APIs, encrypting data for command and control communication is regarded as undetectable to the user.

Log Sources
Data Component Name Channel
Mutable Elements
Field Description

iOS

AN1717

Since data encryption is a common practice in many legitimate applications and uses standard programming language-specific APIs, encrypting data for command and control communication is regarded as undetectable to the user.

Log Sources
Data Component Name Channel
Mutable Elements
Field Description