T1553.005 Mark-of-the-Web Bypass
Sub-technique of T1553 Subvert Trust Controls
Adversaries may abuse specific file formats to subvert Mark-of-the-Web (MOTW) controls. In Windows, when files are downloaded from the Internet, they are tagged with a hidden NTFS Alternate Data Stream (ADS) named Zone.Identifier with a specific value known as the MOTW.(Citation: Microsoft Zone.Identifier 2020) Files that are tagged with MOTW are protected and cannot perform certain actions. For…
Who uses it · with stories on Jábega
Sigma rules to hunt it
- Suspicious Invoke-Item From Mount-DiskImagemediumtest · windows
- Suspicious Unblock-Filemediumtest · windows
- Windows AppX Deployment Full Trust Package Installationmediumexperimental · windows
- Windows AppX Deployment Unsigned Package Installationmediumexperimental · windows
Rules from SigmaHQ · Detection Rule License 1.1. Technique from MITRE ATT&CK®.