// MITRE ATT&CK

T1027 · Obfuscated Files or Information

🎯 Stealth ESXiLinuxmacOSNetwork DevicesWindows

Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit. This is common behavior that can be used across different platforms and the network to evade defenses. Payloads may be ...

¿Cómo detectarlo y mitigarlo?

La detección de Obfuscated Files or Information parte de la telemetría de tu SIEM/EDR. Escribe una regla de detección con el generador Sigma, analiza logs sospechosos en el analizador de logs y sitúa la técnica en tu cobertura con la matriz ATT&CK.

Sub-técnicas (18)

Técnicas relacionadas

Fuente: MITRE ATT&CK®. ATT&CK es una marca registrada de The MITRE Corporation. Contenido con fines educativos.