T1027 Obfuscated Files or Information
Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit. This is common behavior that can be used across different platforms and the network to evade defenses. Payloads may be compressed, archived, or encrypted in order to avoid detection. These payloads may be used during…
Who uses it · with stories on Jábega
Sigma rules to hunt it
- Turla Group Commands May 2020criticaltest · windows
- Potential Emotet Activityhighstable · windows
- Base64 Encoded PowerShell Command Detectedhightest · windows
- Binary Padding - Linuxhightest · linux
- Binary Padding - MacOShightest · macos
- Csc.EXE Execution Form Potentially Suspicious Parenthightest · windows
- File Decoded From Base64/Hex Via Certutil.EXEhightest · windows
- File In Suspicious Location Encoded To Base64 Via Certutil.EXEhightest · windows
- HackTool - CrackMapExec PowerShell Obfuscationhightest · windows
- Invoke-Obfuscation CLIP+ Launcherhightest · windows
- Invoke-Obfuscation CLIP+ Launcher - PowerShellhightest · windows
- Invoke-Obfuscation CLIP+ Launcher - PowerShell Modulehightest · windows
- Invoke-Obfuscation CLIP+ Launcher - Securityhightest · windows
- Invoke-Obfuscation CLIP+ Launcher - Systemhightest · windows
- Invoke-Obfuscation Obfuscated IEX Invocationhightest · windows
- Invoke-Obfuscation Obfuscated IEX Invocation - PowerShellhightest · windows
- Invoke-Obfuscation Obfuscated IEX Invocation - PowerShell Modulehightest · windows
- Invoke-Obfuscation Obfuscated IEX Invocation - Securityhightest · windows
- Invoke-Obfuscation Obfuscated IEX Invocation - Systemhightest · windows
- Invoke-Obfuscation STDIN+ Launcherhightest · windows
- Invoke-Obfuscation STDIN+ Launcher - PowerShell Modulehightest · windows
- Invoke-Obfuscation STDIN+ Launcher - Powershellhightest · windows
- Invoke-Obfuscation STDIN+ Launcher - Securityhightest · windows
- Invoke-Obfuscation STDIN+ Launcher - Systemhightest · windows
- Invoke-Obfuscation VAR+ Launcherhightest · windows
Showing 25 of 61.
Rules from SigmaHQ · Detection Rule License 1.1. Technique from MITRE ATT&CK®.