// MITRE ATT&CK
T1027 · Obfuscated Files or Information
Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit. This is common behavior that can be used across different platforms and the network to evade defenses. Payloads may be ...
¿Cómo detectarlo y mitigarlo?
La detección de Obfuscated Files or Information parte de la telemetría de tu SIEM/EDR. Escribe una regla de detección con el generador Sigma, analiza logs sospechosos en el analizador de logs y sitúa la técnica en tu cobertura con la matriz ATT&CK.
Sub-técnicas (18)
T1027.001
Binary Padding T1027.002
Software Packing T1027.003
Steganography T1027.004
Compile After Delivery T1027.005
Indicator Removal from Tools T1027.006
HTML Smuggling T1027.007
Dynamic API Resolution T1027.008
Stripped Payloads T1027.009
Embedded Payloads T1027.010
Command Obfuscation T1027.011
Fileless Storage T1027.012
LNK Icon Smuggling T1027.013
Encrypted/Encoded File T1027.014
Polymorphic Code T1027.015
Compression T1027.016
Junk Code Insertion T1027.017
SVG Smuggling T1027.018
Invisible Unicode
Binary Padding T1027.002
Software Packing T1027.003
Steganography T1027.004
Compile After Delivery T1027.005
Indicator Removal from Tools T1027.006
HTML Smuggling T1027.007
Dynamic API Resolution T1027.008
Stripped Payloads T1027.009
Embedded Payloads T1027.010
Command Obfuscation T1027.011
Fileless Storage T1027.012
LNK Icon Smuggling T1027.013
Encrypted/Encoded File T1027.014
Polymorphic Code T1027.015
Compression T1027.016
Junk Code Insertion T1027.017
SVG Smuggling T1027.018
Invisible Unicode
Técnicas relacionadas
T1055.011
Extra Window Memory Injection T1205.002
Socket Filters T1027.011
Fileless Storage T1218.011
Rundll32 T1027.009
Embedded Payloads T1564.012
File/Path Exclusions T1216.001
PubPrn T1574.007
Path Interception by PATH Environment Variable
Extra Window Memory Injection T1205.002
Socket Filters T1027.011
Fileless Storage T1218.011
Rundll32 T1027.009
Embedded Payloads T1564.012
File/Path Exclusions T1216.001
PubPrn T1574.007
Path Interception by PATH Environment Variable
Fuente: MITRE ATT&CK®. ATT&CK es una marca registrada de The MITRE Corporation. Contenido con fines educativos.