LiveActive security incident?Get immediate response
MITRE ATT&CK® Detection Strategy

DET0326: Behavior-chain detection for T1132.002 Data Encoding: Non-Standard Encoding across Windows, Linux, macOS, ESXi

MITRE ATT&CK DET0326: Behavior-chain detection for T1132.002 Data Encoding: Non-Standard Encoding across Windows, Linux, macOS, ESXi Detection Strategy details,…

EnterpriseDET0326Detection StrategyObject v1.0Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

This detection strategy is about finding command-and-control activity that hides data using non-standard encoding. For leaders, the issue is not the encoding itself; it is that adversaries may alter expected protocol formats to make outbound C2 traffic harder for normal content matching and inspection to recognize across Windows, Linux, macOS, and ESXi environments.

Executive priority

Prioritize this as an egress visibility and SOC validation problem. Security leaders should ask whether the organization can prove it monitors outbound traffic patterns, inspects relevant protocol metadata where appropriate, and has response procedures for suspicious encoded C2-like communications. It is especially useful for resilience, audit evidence, and IR readiness because weak outbound telemetry can leave defenders unable to explain what systems communicated externally during an incident.

Technical view

DET0326 detects T1132.002, Non-Standard Encoding, under command-and-control. Because no official ATT&CK detection text is provided for this detection strategy, teams should validate behavior-chain coverage by correlating suspicious outbound network activity with protocol content or metadata that diverges from expected encoding formats, such as modified Base64-like data in HTTP request bodies. Coverage should be checked across the related platforms: Windows, Linux, macOS, and ESXi.

Likely telemetry

  • Outbound network flow records from endpoints and servers
  • Proxy, firewall, and secure web gateway logs
  • HTTP request metadata and request body inspection where legally and operationally available
  • Endpoint process-to-network connection telemetry for Windows, Linux, macOS, and ESXi systems
  • Network sensor alerts or packet-derived protocol metadata showing unusual encoding or protocol deviations

Detection direction

  • Validate whether detections look for behavior chains, not only static signatures, because non-standard encoding may be designed to evade simple content matching.
  • Tune detections around unexpected encoding patterns in C2-relevant traffic while accounting for legitimate custom applications, APIs, and middleware that may use proprietary encodings.
  • Correlate encoded outbound content with destination reputation, process lineage, host role, user context, and unusual timing or volume where those data sources exist.
  • Confirm visibility for ESXi and non-Windows systems; these are common blind spots if endpoint telemetry is Windows-centric.
  • Document where payload inspection is unavailable due to encryption, privacy limits, or logging constraints, and compensate with metadata-based analytics.

Mitigation priorities

  • Establish baseline egress paths and require centralized logging for outbound web and network traffic.
  • Limit direct outbound access from servers and infrastructure platforms where business operations allow.
  • Maintain SOC playbooks for suspicious encoded C2-like traffic, including host isolation, process review, and external destination scoping.
  • Use change management and application inventory to identify legitimate custom encodings so detections can be tuned without suppressing meaningful anomalies.
  • Preserve relevant network and endpoint telemetry for incident response and compliance evidence.
Additional notes and limits

The ATT&CK object provides the detection strategy name, external reference, and relationship to T1132.002, but does not include an official description or official detection guidance. The most useful defensive interpretation is therefore relationship-driven: validate whether controls can identify command-and-control traffic using encoding that diverges from expected protocol specifications.

This take does not assert active exploitation, actor attribution, guaranteed detection, or implemented coverage. Local network architecture, encryption, logging policy, privacy constraints, and platform telemetry determine how much of this behavior can actually be observed.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Behavior-chain detection for T1132.002 Data Encoding: Non-Standard Encoding across Windows, Linux, macOS, ESXi

No official description is available in the imported ATT&CK source object.

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

1 rows
DomainIDNameRelationship / procedure
EnterpriseT1132.002Non-Standard EncodingSub-techniqueThis object detects Non-Standard Encoding.
Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.0
Created
Modified
Raw hash
0564c4ee690c8094...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.0Current bundle0564c4ee690c…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    mitre-attackDET0326
    Open source URL
  2. [2]
    mitre-attackDET0326
    Open source URL
  3. [3]
    mitre-attackDET0326
    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.