T1027.010 Command Obfuscation
Sub-technique of T1027 Obfuscated Files or Information
Adversaries may obfuscate content during command execution to impede detection. Command-line obfuscation is a method of making strings and patterns within commands and scripts more difficult to signature and analyze. This type of obfuscation can be included within commands executed by delivered payloads (e.g., [Phishing](https://attack.mitre.org/techniques/T1566) and [Drive-by…
Who uses it · with stories on Jábega
Sigma rules to hunt it
- Obfuscated PowerShell MSI Install via WindowsInstaller COMhighexperimental · windows
- Python One-Liners with Base64 Decodinghighexperimental · windows
- Python One-Liners with Base64 Decoding - Linuxhighexperimental · linux
- Suspicious Explorer Process with Whitespace Padding - ClickFix/FileFixhighexperimental · windows
- Suspicious Space Characters in RunMRU Registry Path - ClickFixhighexperimental · windows
- Suspicious Space Characters in TypedPaths Registry Path - FileFixhighexperimental · windows
- Potential Obfuscated Ordinal Call Via Rundll32mediumtest · windows
- Suspicious Usage of For Loop with Recursive Directory Search in CMDmediumexperimental · windows
Rules from SigmaHQ · Detection Rule License 1.1. Technique from MITRE ATT&CK®.