T1140 Deobfuscate/Decode Files or Information
Adversaries may use [Obfuscated Files or Information](https://attack.mitre.org/techniques/T1027) to hide artifacts of an intrusion from analysis. They may require separate mechanisms to decode or deobfuscate that information depending on how they intend to use it. Methods for doing that include built-in functionality of malware or by using utilities present on the system. One such example is the…
Quién la usa · con noticias en Jábega
Reglas Sigma para cazarla
- Base64 Encoded PowerShell Command Detectedhightest · windows
- MSHTA Execution with Suspicious File Extensionshightest · windows
- Ping Hex IPhightest · windows
- Potential Base64 Decoded From Imageshightest · macos
- Potential BlackByte Ransomware Activityhightest · windows
- PowerShell Base64 Encoded FromBase64String Cmdlethightest · windows
- Suspicious Inbox Manipulation Ruleshightest · azure
- UNC4841 - Download Compressed Files From Temp.sh Using Wgethightest · linux
- UNC4841 - Download Tar File From Untrusted Direct IP Via Wgethightest · linux
- UNC4841 - SSL Certificate Exfiltration Via Opensslhightest · linux
- DNS-over-HTTPS Enabled by Registrymediumtest · windows
- Linux Base64 Encoded Pipe to Shellmediumtest · linux
- Linux Base64 Encoded Shebang In CLImediumtest · linux
- Linux Shell Pipe to Shellmediumtest · linux
- Payload Decoded and Decrypted via Built-in Utilitiesmediumtest · macos
- Potential Commandline Obfuscation Using Escape Charactersmediumtest · windows
- Suspicious XOR Encoded PowerShell Commandmediumtest · windows
Reglas de SigmaHQ · Detection Rule License 1.1. Técnica de MITRE ATT&CK®.