Payload Channel Operating Without Encryption

Monitors payload channels for unencrypted data exchanges that could indicate improper configuration or security degradation. Typically, the payload data is encrypted and an adversary may attempt to put payload into clear mode to further attacks.

STIX Pattern

[network-traffic:src_ref.value = 'payload_channel' AND network-traffic:encryption_status != 'encrypted']

SPARTA TTPs

ID Name Description