DET0326: Behavior-chain detection for T1132.002 Data Encoding: Non-Standard Encoding across Windows, Linux, macOS, ESXi
MITRE ATT&CK DET0326: Behavior-chain detection for T1132.002 Data Encoding: Non-Standard Encoding across Windows, Linux, macOS, ESXi Detection Strategy details,…
Security context for executives and security teams
This detection strategy is about finding command-and-control activity that hides data using non-standard encoding. For leaders, the issue is not the encoding itself; it is that adversaries may alter expected protocol formats to make outbound C2 traffic harder for normal content matching and inspection to recognize across Windows, Linux, macOS, and ESXi environments.
Executive priority
Prioritize this as an egress visibility and SOC validation problem. Security leaders should ask whether the organization can prove it monitors outbound traffic patterns, inspects relevant protocol metadata where appropriate, and has response procedures for suspicious encoded C2-like communications. It is especially useful for resilience, audit evidence, and IR readiness because weak outbound telemetry can leave defenders unable to explain what systems communicated externally during an incident.
Technical view
DET0326 detects T1132.002, Non-Standard Encoding, under command-and-control. Because no official ATT&CK detection text is provided for this detection strategy, teams should validate behavior-chain coverage by correlating suspicious outbound network activity with protocol content or metadata that diverges from expected encoding formats, such as modified Base64-like data in HTTP request bodies. Coverage should be checked across the related platforms: Windows, Linux, macOS, and ESXi.
Likely telemetry
- Outbound network flow records from endpoints and servers
- Proxy, firewall, and secure web gateway logs
- HTTP request metadata and request body inspection where legally and operationally available
- Endpoint process-to-network connection telemetry for Windows, Linux, macOS, and ESXi systems
- Network sensor alerts or packet-derived protocol metadata showing unusual encoding or protocol deviations
Detection direction
- Validate whether detections look for behavior chains, not only static signatures, because non-standard encoding may be designed to evade simple content matching.
- Tune detections around unexpected encoding patterns in C2-relevant traffic while accounting for legitimate custom applications, APIs, and middleware that may use proprietary encodings.
- Correlate encoded outbound content with destination reputation, process lineage, host role, user context, and unusual timing or volume where those data sources exist.
- Confirm visibility for ESXi and non-Windows systems; these are common blind spots if endpoint telemetry is Windows-centric.
- Document where payload inspection is unavailable due to encryption, privacy limits, or logging constraints, and compensate with metadata-based analytics.
Mitigation priorities
- Establish baseline egress paths and require centralized logging for outbound web and network traffic.
- Limit direct outbound access from servers and infrastructure platforms where business operations allow.
- Maintain SOC playbooks for suspicious encoded C2-like traffic, including host isolation, process review, and external destination scoping.
- Use change management and application inventory to identify legitimate custom encodings so detections can be tuned without suppressing meaningful anomalies.
- Preserve relevant network and endpoint telemetry for incident response and compliance evidence.
Additional notes and limits
The ATT&CK object provides the detection strategy name, external reference, and relationship to T1132.002, but does not include an official description or official detection guidance. The most useful defensive interpretation is therefore relationship-driven: validate whether controls can identify command-and-control traffic using encoding that diverges from expected protocol specifications.
This take does not assert active exploitation, actor attribution, guaranteed detection, or implemented coverage. Local network architecture, encryption, logging policy, privacy constraints, and platform telemetry determine how much of this behavior can actually be observed.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Behavior-chain detection for T1132.002 Data Encoding: Non-Standard Encoding across Windows, Linux, macOS, ESXi
No official description is available in the imported ATT&CK source object.
How security teams should use this page
Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.
Techniques used
This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.
| Domain | ID | Name | Relationship / procedure |
|---|---|---|---|
| Enterprise | T1132.002 | Non-Standard EncodingSub-technique | This object detects Non-Standard Encoding. |
All related ATT&CK context
Object version and sync metadata
The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.
Imported snapshots across ATT&CK releases(1)
| Release | Bundle imported | Object version | Modified | Status | Raw hash |
|---|---|---|---|---|---|
| 19.1 | 1.0 | Current bundle | 0564c4ee690c… |
Mirrored ATT&CK source object
The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.
External references and citations
MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.
- [1]mitre-attackDET0326Open source URL
- [2]mitre-attackDET0326Open source URL
- [3]mitre-attackDET0326Open source URL
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
