// MITRE ATT&CK
T1027 · Obfuscated Files or Information
Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit. This is common behavior that can be used across different platforms and the network to evade defenses. Payloads may be ...
How to detect & mitigate it
Detecting Obfuscated Files or Information starts with your SIEM/EDR telemetry. Write a detection rule with the Sigma generator, analyze suspicious logs in the log analyzer, and place the technique on your coverage with the ATT&CK matrix.
Sub-techniques (18)
T1027.001
Binary Padding T1027.002
Software Packing T1027.003
Steganography T1027.004
Compile After Delivery T1027.005
Indicator Removal from Tools T1027.006
HTML Smuggling T1027.007
Dynamic API Resolution T1027.008
Stripped Payloads T1027.009
Embedded Payloads T1027.010
Command Obfuscation T1027.011
Fileless Storage T1027.012
LNK Icon Smuggling T1027.013
Encrypted/Encoded File T1027.014
Polymorphic Code T1027.015
Compression T1027.016
Junk Code Insertion T1027.017
SVG Smuggling T1027.018
Invisible Unicode
Binary Padding T1027.002
Software Packing T1027.003
Steganography T1027.004
Compile After Delivery T1027.005
Indicator Removal from Tools T1027.006
HTML Smuggling T1027.007
Dynamic API Resolution T1027.008
Stripped Payloads T1027.009
Embedded Payloads T1027.010
Command Obfuscation T1027.011
Fileless Storage T1027.012
LNK Icon Smuggling T1027.013
Encrypted/Encoded File T1027.014
Polymorphic Code T1027.015
Compression T1027.016
Junk Code Insertion T1027.017
SVG Smuggling T1027.018
Invisible Unicode
Related techniques
T1055.011
Extra Window Memory Injection T1205.002
Socket Filters T1027.011
Fileless Storage T1218.011
Rundll32 T1027.009
Embedded Payloads T1564.012
File/Path Exclusions T1216.001
PubPrn T1574.007
Path Interception by PATH Environment Variable
Extra Window Memory Injection T1205.002
Socket Filters T1027.011
Fileless Storage T1218.011
Rundll32 T1027.009
Embedded Payloads T1564.012
File/Path Exclusions T1216.001
PubPrn T1574.007
Path Interception by PATH Environment Variable
Source: MITRE ATT&CK®. ATT&CK is a registered trademark of The MITRE Corporation. Content for educational purposes.